Description
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 are vulnerable to a cross-site request forgery attack, because they use the HTTP method `GET` to change state on the server. Version 2.4.28 contains a patch.
Problem types
CWE-650: Trusting HTTP Permission Methods on the Server Side
Product status
References
www.openwall.com/lists/oss-security/2026/05/19/11
github.com/...is-web/security/advisories/GHSA-m73w-v4r5-vw9m