CVE-2024-23319: Mattermost Server
Low severity, CVSS 3.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection in Mattermost only by viewing the message.
Affected products
- Mattermost Mattermost Server: up to and including 8.1.7
Published 2024-02-09. Last modified 2026-06-17.