CVE-2024-23737: CSRF
Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23737?
CVE-2024-23737 has been rated as a medium severity vulnerability due to the potential for unauthorized manipulation of user certificates.
How do I fix CVE-2024-23737?
To fix CVE-2024-23737, upgrade to version 4.0.2 or later of the savignano S/Notify software.
What types of software are affected by CVE-2024-23737?
CVE-2024-23737 affects savignano S/Notify versions before 4.0.2 for Jira, Bitbucket, and Confluence.
What does CVE-2024-23737 exploit?
CVE-2024-23737 exploits a Cross Site Request Forgery (CSRF) vulnerability allowing attackers to manipulate a user's S/MIME certificate or PGP key.
How can attackers leverage CVE-2024-23737?
Attackers can leverage CVE-2024-23737 via a malicious link or email to alter a user's cryptographic keys.