CVE-2023-30607

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-30607
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-30607.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-30607
Aliases
  • GHSA-gh7w-7f7j-gwp5
Published
2023-07-05T17:42:54Z
Modified
2025-10-22T18:36:50.660805Z
Severity
  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L CVSS Calculator
Summary
icingaweb2-module-jira template and field configuration are susceptible to CSRF
Details

icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, template and field configuration forms perform the deletion action before user input is validated, including the cross site request forgery token. This issue is fixed in version 1.3.2. There are no known workarounds.

Database specific
{
    "cwe_ids": [
        "CWE-352"
    ]
}
References

Affected packages

Git / github.com/icinga/icingaweb2-module-jira

Affected ranges

Type
GIT
Repo
https://github.com/icinga/icingaweb2-module-jira
Events

Affected versions

v1.*

v1.3.0
v1.3.1