CVE-2024-23319: Mattermost Server

Low severity, CVSS 3.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection in Mattermost only by viewing the message.

Affected products

  • Mattermost Mattermost Server: up to and including 8.1.7

Published 2024-02-09. Last modified 2026-06-17.