CVE-2024-24774
Last modified
CVE-2024-24774 is a medium-severity vulnerability rated 4.1/10 on the CVSS scale. Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the subscription resulting in registered users on Jira being able to create webhooks that give them access to all Jira issues. . EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the subscription resulting in registered users on Jira being able to create webhooks that give them access to all Jira issues.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mattermost | Mattermost Server | <= 8.1.7 |
References
- https://mattermost.com/security-updatesVendor Advisory
- https://mattermost.com/security-updatesVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-24774?
How severe is CVE-2024-24774?
How do I fix CVE-2024-24774?
Are you affected by CVE-2024-24774?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
