Launch Week Day 1: Announcing Security Design Review
LOW 3.5 Go

Mattermost Jira Plugin vulnerable to Cross-Site Request Forgery

GHSA-4fp6-574p-fc35 · BIT-mattermost-2024-23319 · CVE-2024-23319 · GO-2024-2539

Published · Modified

Description

Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection in Mattermost only by viewing the message.

Ready to move

Start Securing

Free, no credit card | First findings in minutes