ZeroHour

CVE-2024-24774

CVSS 3.1
4.1 medium
EPSS
<1%p38
Published
()
Modified
Description

Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the subscription resulting in registered users on Jira being able to create webhooks that give them access to all Jira issues.

Vendors
mattermost
Products
mattermost server
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.