« Volver al listado

CVE-2024-2445

Estado: AnalizadaMedia (6.1)—

Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to escape user-controlled outputs when generating HTML pages, which allows an attacker to perform reflected cross-site scripting attacks against the users of the Mattermost server.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-2445",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-2445",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-03-18T18:53:41.753419Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "responsibledisclosure@mattermost.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "responsibledisclosure@mattermost.com",
      "affectedData": [
        {
          "vendor": "Mattermost",
          "product": "Mattermost",
          "versions": [
            {
              "status": "affected",
              "version": "9.4.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.4.2"
            },
            {
              "status": "affected",
              "version": "9.3.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.3.1"
            },
            {
              "status": "affected",
              "version": "9.2.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.2.5"
            },
            {
              "status": "affected",
              "version": "8.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.1.9"
            },
            {
              "status": "unaffected",
              "version": "9.5.0"
            },
            {
              "status": "unaffected",
              "version": "9.4.3"
            },
            {
              "status": "unaffected",
              "version": "9.3.2"
            },
            {
              "status": "unaffected",
              "version": "9.2.6"
            },
            {
              "status": "unaffected",
              "version": "8.1.10"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-03-15T10:15:07.923",
  "references": [
    {
      "url": "https://mattermost.com/security-updates",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "responsibledisclosure@mattermost.com"
    },
    {
      "url": "https://mattermost.com/security-updates",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "responsibledisclosure@mattermost.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-74"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to escape user-controlled outputs when generating HTML pages, which allows an attacker to perform reflected cross-site scripting attacks against the users of the Mattermost server.\n\n"
    },
    {
      "lang": "es",
      "value": "Las versiones del complemento Mattermost Jira enviadas con las versiones 8.1.x anteriores a 8.1.10, 9.2.x anteriores a 9.2.6, 9.3.x anteriores a 9.3.2 y 9.4.x anteriores a 9.4.3 no logran escapar de las salidas controladas por el usuario al generar HTML. páginas, lo que permite a un atacante realizar ataques de cross-site scripting reflejados contra los usuarios del servidor Mattermost."
    }
  ],
  "lastModified": "2026-06-17T07:24:33.060",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0ADAC025-32F2-4971-81F3-4D2939890060",
              "versionEndExcluding": "8.1.10",
              "versionStartIncluding": "8.1.0"
            },
            {
              "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71A20DFB-85FA-480C-956A-24B50AB1862D",
              "versionEndExcluding": "9.2.6",
              "versionStartIncluding": "9.2.0"
            },
            {
              "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA0D2B39-6A65-4B91-925D-20087EF4CCB9",
              "versionEndExcluding": "9.3.2",
              "versionStartIncluding": "9.3.0"
            },
            {
              "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74D75B50-ED53-47E4-A43A-1D3D8CFE4F8E",
              "versionEndExcluding": "9.4.3",
              "versionStartIncluding": "9.4.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "responsibledisclosure@mattermost.com"
}