PT-2024-19806 · Mattermost · Mattermost Jira Plugin

Rohitesh Gupta

·

Published

2024-02-09

·

Updated

2024-03-18

·

CVE-2024-23319

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Mattermost Jira Plugin (affected versions not specified)
Description The Mattermost Jira Plugin fails to protect against logout CSRF, allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection in Mattermost by simply viewing the message. This issue can be exploited via a cross-site request forgery vulnerability in the logout button.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2024-23319
CVE-2024-23319
GHSA-4FP6-574P-FC35
GO-2024-2539

Affected Products

Mattermost Jira Plugin