CVE-2024-24774

CVSS 3.1 Score 4.1 of 10 (medium)

Details

Published Feb 9, 2024
Updated: Feb 15, 2024
CWE ID 863

Summary

CVE-2024-24774 is a vulnerability affecting the Mattermost Jira Plugin. This issue arises from the plugin's failure to properly verify the security level of incoming issues or limit them based on the user who created the subscription. Consequently, registered users on Jira can create webhooks that grant them access to all Jira issues, potentially leading to unintended data exposure or manipulation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share