Vulnerability Report: GO-2024-2539
- CVE-2024-23319, GHSA-4fp6-574p-fc35
- Affects: github.com/mattermost/mattermost-plugin-jira
- Published: Mar 18, 2024
- Modified: Jul 09, 2024
Cross-site request forgery via logout button in github.com/mattermost/mattermost-plugin-jira
For detailed information about this vulnerability, visit https://nvd.nist.gov/vuln/detail/CVE-2024-23319.
Affected Packages
-
PathGo VersionsCustom Versions*Symbols
-
before v1.1.2-0.20230830170046-f4cf4c6de017before 4.0.0-rc2
2 unexported affected symbols
- Plugin.httpOAuth1aDisconnect
- Plugin.initializeRouter
*Custom versions, which can't be mapped automatically to standard Go module versions, are ignored by govulncheck
. (See this note on versions for more details.)
Aliases
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-23319
- https://github.com/mattermost/mattermost-plugin-jira/commit/f4cf4c6de017ef6aa4428d393b78f418dd84cd8e
- https://mattermost.com/security-updates
- https://vuln.go.dev/ID/GO-2024-2539.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.