Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-72761

Replay attack via the CSRF failure retry form - CVE-2021-39124

    • 4.3
    • Medium
    • CVE-2021-39124

      The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request.

      *Affected versions:*

      • version < 8.16.0

      *Fixed versions:*

      • 8.16.0

            [JRASERVER-72761] Replay attack via the CSRF failure retry form - CVE-2021-39124

            Cathy S made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 689965 ]
            Cathy S made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 626685 ]
            David Black made changes -
            CVSS Severity Original: Low [ 16632 ] New: Medium [ 16633 ]
            David Black made changes -
            CVSS Score Original: 3.1 New: 4.3
            Cathy S made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 622626 ]
            Cathy S made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 618566 ]
            Geoff made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 589045 ]

            This issue has been assigned Qualys QID 730196 and a Severity of 3

             

            Russell Berry added a comment - This issue has been assigned Qualys QID 730196 and a Severity of 3  
            Security Metrics Bot made changes -
            CVE ID New: CVE-2021-39124
            AB made changes -
            Security Original: Atlassian Staff [ 10750 ]

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: