CVE-2019-15002
11.02.2025, 18:15
An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesnt require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.
Vendor | Product | Version |
---|---|---|
atlassian | jira_data_center | 7.6.4 ≤ 𝑥 ≤ 8.1.0 |
atlassian | jira_server | 7.6.4 ≤ 𝑥 ≤ 8.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration