Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-44198

CSRF vulnerability in the issue collector

    XMLWordPrintable

Details

    Description

      NOTE: This bug report is for JIRA Server. Using JIRA Cloud? See the corresponding bug report.

      The JIRA issue collector REST API is vulnerable to CSRF:

      curl -X POST 'https://example.com/rest/collectors/1.0/template/custom/<collector_id>' --data 'pid=<project_id>&summary=testwithcurl&description=mydesc'
      

      Attachments

        Issue Links

          Activity

            People

              pklimkowski@atlassian.com Piotr Klimkowski (Inactive)
              lmiranda Luis Miranda (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: