Uploaded image for project: 'Bitbucket Data Center'
  1. Bitbucket Data Center
  2. BSERV-5336

TemporaryAvatarController.save is vulnerable to CSRF/XSRF

    XMLWordPrintable

Details

    Description

      As pointed out in STASH-5335, the
      TemporaryAvatarController.save resource is vulnerable to CSRF. Currently there appears to be no impact of it being vulnerable except for making a user upload a temporary avatar file (which are periodically deleted).

      Attachments

        Issue Links

          Activity

            People

              mszczepanski Marcin
              dblack David Black
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: