CVE-2023-44384
Last modified
CVE-2023-44384 is a medium-severity vulnerability rated 4.1/10 on the CVSS scale. Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automatically. An administrator user can make an SSRF attack by setting the Jira URL to an arbitrary location and enabling the `discourse_jira_verbose_log` site setting. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automatically. An administrator user can make an SSRF attack by setting the Jira URL to an arbitrary location and enabling the `discourse_jira_verbose_log` site setting. A moderator user could manipulate the request path to the Jira API, allowing them to perform arbitrary GET requests using the Jira API credentials, potentially with elevated permissions, used by the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Discourse | Discourse Jira | <= 2023-10-01 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-44384?
How severe is CVE-2023-44384?
How do I fix CVE-2023-44384?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-44378gnark is a zk-SNARK library that offers a high-level API to …5.5
- CVE-2023-44379baserCMS is a website development framework. Prior to versio…6.1
- CVE-2023-4438A vulnerability has been found in SourceCodester Inventory M…9.8
- CVE-2023-44381October is a Content Management System (CMS) and web platfor…4.9
- CVE-2023-44382October is a Content Management System (CMS) and web platfor…9.1
- CVE-2023-44383October is a Content Management System (CMS) and web platfor…5.4
- CVE-2023-44385The Home Assistant Companion for iOS and macOS app up to ver…8.8
- CVE-2023-44386Vapor is an HTTP web framework for Swift. There is a denial …5.3
- CVE-2023-44387Gradle is a build tool with a focus on build automation and …6.5
- CVE-2023-44388Discourse is an open source platform for community discussio…7.5
- CVE-2023-44389Zope is an open-source web application server. The title pro…4.8
- CVE-2023-4439A vulnerability was found in SourceCodester Card Holder Mana…5.3
Are you affected by CVE-2023-44384?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
