LOW 3.5 Go

Mattermost Jira Plugin vulnerable to Cross-Site Request Forgery

GHSA-4fp6-574p-fc35 · BIT-mattermost-2024-23319 · CVE-2024-23319 · GO-2024-2539

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection in Mattermost only by viewing the message.

Ready to move

Start Securing

Free, no credit card | First findings in minutes