CWE
918 691
Advisory Published
Updated

CVE-2023-44384: Discourse-Jira could make SSRF attack by setting Jira URL to an arbitrary location

First published: Fri Oct 06 2023(Updated: )

Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automatically. An administrator user can make an SSRF attack by setting the Jira URL to an arbitrary location and enabling the `discourse_jira_verbose_log` site setting. A moderator user could manipulate the request path to the Jira API, allowing them to perform arbitrary GET requests using the Jira API credentials, potentially with elevated permissions, used by the application.

Credit: security-advisories@github.com security-advisories@github.com

Affected SoftwareAffected VersionHow to fix
Discourse Discourse Jira<=2023-10-01

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2023-44384?

    CVE-2023-44384 is a vulnerability in the Discourse-jira plugin that allows an administrator user to perform a Server-Side Request Forgery (SSRF) attack by manipulating the Jira URL.

  • How severe is CVE-2023-44384?

    CVE-2023-44384 has a severity rating of 4.1, which is classified as medium.

  • What is Discourse-jira?

    Discourse-jira is a plugin for Discourse that enables synchronization of Jira projects, issue types, fields, and field options.

  • What is an SSRF attack?

    SSRF stands for Server-Side Request Forgery, which is a type of vulnerability that allows an attacker to make requests from the vulnerable server to internal or external network resources.

  • How can an administrator user perform an SSRF attack using CVE-2023-44384?

    An administrator user can perform an SSRF attack by setting the Jira URL to a malicious location and enabling the `discourse_jira_verbose_log` site setting.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203