Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-36680

XSRF - complete task request omits atl-token

    XMLWordPrintable

Details

    Description

      Potential XSRF vulnerability in tasks. No atl-token is present in the request to complete a task which suggests an attacker may be able to craft a cross site request forgery and action a task without the correct authorisation.

      Attachments

        Issue Links

          Activity

            People

              tthanhdang Tung Dang
              dpabst Dee (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: