Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-22784

logout.action is not protected against XSRF - CVE-2012-6342

    XMLWordPrintable

Details

    Description

      Cross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allows remote attackers to hijack the authentication of administrators, for requests that logout the user via a comment.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              69c7542de932 Robert Gilbert
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: