-
Bug
-
Resolution: Fixed
-
Low (View bug fix roadmap)
-
7.6.15, 8.3.3, 7.13.8, 8.5.0
-
7.06
-
Severity 2 - Major
-
Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF) vulnerabilities.
Once a Jira instance is setup (i.e. database, admin account, licence, etc. form are filled) the vulnerability can't be exploited anymore.
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 5.9 => Medium severity
Exploitability Metrics
Scope Metric
Impact Metrics
https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L