CVE-2023-44384
Last modified
CVE-2023-44384 is a medium-severity vulnerability rated 4.1/10 on the CVSS scale. Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automatically. An administrator user can make an SSRF attack by setting the Jira URL to an arbitrary location and enabling the `discourse_jira_verbose_log` site setting. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automatically. An administrator user can make an SSRF attack by setting the Jira URL to an arbitrary location and enabling the `discourse_jira_verbose_log` site setting. A moderator user could manipulate the request path to the Jira API, allowing them to perform arbitrary GET requests using the Jira API credentials, potentially with elevated permissions, used by the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Discourse | Discourse Jira | <= 2023-10-01 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-44384?
How severe is CVE-2023-44384?
How do I fix CVE-2023-44384?
Are you affected by CVE-2023-44384?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
