CVE-2023-30607

MEDIUM

Icinga Web Jira Integration < 1.3.2 - CSRF

Title source: rule
STIX 2.1

Description

icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, template and field configuration forms perform the deletion action before user input is validated, including the cross site request forgery token. This issue is fixed in version 1.3.2. There are no known workarounds.

Scores

CVSS v3 5.0
EPSS 0.0015
EPSS Percentile 35.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
icinga/icinga_web_jira_integration 1.3.0 - 1.3.2
Published Jul 05, 2023
Tracked Since Feb 18, 2026