Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-30607


icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, template and field configuration forms perform the deletion action before user input is validated, including the cross site request forgery token. This issue is fixed in version 1.3.2. There are no known workarounds.


Published

2023-07-05T18:15:10.070

Last Modified

2024-11-21T08:00:29.740

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.0 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application icinga icinga_web_jira_integration < 1.3.2 Yes

References