PT-2024-20552 · Atlassian+1 · Jira+2

Michael Kochell

·

Published

2024-02-09

·

Updated

2024-06-28

·

CVE-2024-24774

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mattermost Jira Plugin versions prior to 4.0.0-rc1 Mattermost versions up to 8.1.7
Description The Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the subscription. This results in registered users on Jira being able to create webhooks that give them access to all Jira issues.
Recommendations For Mattermost Jira Plugin versions prior to 4.0.0-rc1, update to version 4.0.0-rc1 or later to resolve the issue. For Mattermost versions up to 8.1.7, update to a version later than 8.1.7 to resolve the issue. As a temporary workaround, consider restricting access to the Jira Plugin to minimize the risk of exploitation.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2024-24774
CVE-2024-24774
GHSA-QR8F-CJW7-838M
GO-2024-2540

Affected Products

Jira
Mattermost
Mattermost Jira Plugin