-
Bug
-
Resolution: Fixed
-
Low
-
8.2.4, 7.13.6
-
7.13
-
Severity 2 - Major
-
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cross-site request forgery (CSRF) vulnerability.
Affected versions:
- version < 7.13.9
- 8.0.0 ≤ version < 8.4.2
Fixed versions:
- 7.13.9
- 8.4.2
- 8.5.0
[JRASERVER-70881] CSRF on Wallboard endpoint - CVE-2019-20411
Labels | Original: CVE-2019-20411 advisory advisory-to-release bugbash2 bugbounty csrf cvss-medium security xsrf | New: CVE-2019-20411 advisory advisory-released bugbash2 bugbounty csrf cvss-medium security xsrf |
Labels | Original: advisory advisory-to-release bugbash2 bugbounty csrf cve-in-progress cvss-medium security xsrf | New: CVE-2019-20411 advisory advisory-to-release bugbash2 bugbounty csrf cvss-medium security xsrf |
Summary | Original: CSRF on Wallboard endpoint | New: CSRF on Wallboard endpoint - CVE-2019-20411 |
Labels | Original: advisory advisory-to-release bugbash2 bugbounty csrf cvss-medium security xsrf | New: advisory advisory-to-release bugbash2 bugbounty csrf cve-in-progress cvss-medium security xsrf |
Fixed in Enterprise Release/s | New: [Download 7.13, 8.5|https://confluence.atlassian.com/enterprise/atlassian-enterprise-releases-948227420.html] |
Introduced in Version | New: 7.13 |
Due Date | New: 07/Jul/2020 |
Security | Original: Atlassian Staff [ 10750 ] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Needs Triage [ 10030 ] | New: Closed [ 6 ] |
Description |
Original:
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cross-site request forgery (CSRF) vulnerability.
*Affected versions:* * version < 7.13.9 * 8.0.0 ≤ version < 8.4.2 *Fixed versions:* * **7.13.9 * 8.4.2 * 8.5.0 |
New:
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cross-site request forgery (CSRF) vulnerability.
*Affected versions:* * version < 7.13.9 * 8.0.0 ≤ version < 8.4.2 *Fixed versions:* * 7.13.9 * 8.4.2 * 8.5.0 |