Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-09864
HistoryFeb 22, 2024 - 12:00 a.m.

Mattermost Cross-Site Request Forgery Vulnerability (CNVD-2024-09864)

2024-02-2200:00:00
China National Vulnerability Database
www.cnvd.org.cn
4
mattermost
cross-site request forgery
vulnerability
jira plugin
united states
attack
specially crafted message
disconnect

6.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.3%

Mattermost is an open source collaboration platform from Mattermost, Inc. in the United States. Mattermost suffers from a cross-site request forgery vulnerability that stems from the Jira plugin’s inability to prevent logout CSRF, which can be exploited by an attacker to post a specially crafted message that disconnects a user from Jira in Mattermost just by viewing the message.

CPENameOperatorVersion
mattermost mattermost serverle8.1.7

6.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.3%