CVE-2024-2445: Reflected XSS in Mattermost Jira plugin
Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to escape user-controlled outputs when generating HTML pages, which allows an attacker to perform reflected cross-site scripting attacks against the users of the Mattermost server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2445?
CVE-2024-2445 has been assigned a severity rating that reflects the potential impact of reflected cross-site scripting vulnerability in Mattermost Jira plugin.
How do I fix CVE-2024-2445?
To fix CVE-2024-2445, upgrade Mattermost to versions 8.1.10, 9.2.6, 9.3.2, or 9.4.3 or later.
Which versions of Mattermost are affected by CVE-2024-2445?
CVE-2024-2445 affects Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3.
What type of vulnerability is CVE-2024-2445?
CVE-2024-2445 is a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts.
Can I still use Mattermost with CVE-2024-2445 present?
While you can technically continue using Mattermost with CVE-2024-2445, it is highly recommended to update to a patched version to ensure security.