CVE-2024-23319

Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection in Mattermost only by viewing the message.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:57

Type Values Removed Values Added
References () https://mattermost.com/security-updates - Vendor Advisory () https://mattermost.com/security-updates - Vendor Advisory

15 Feb 2024, 18:44

Type Values Removed Values Added
CPE cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
Summary
  • (es) El complemento Mattermost Jira no protege contra el cierre de sesión CSRF, lo que permite a un atacante publicar un mensaje especialmente manipulado que desconectaría la conexión Jira de un usuario en Mattermost solo al ver el mensaje.
First Time Mattermost mattermost Server
Mattermost

09 Feb 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-09 15:15

Updated : 2024-11-21 08:57


NVD link : CVE-2024-23319

Mitre link : CVE-2024-23319

CVE.ORG link : CVE-2024-23319


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-352

Cross-Site Request Forgery (CSRF)