-
Public Security Vulnerability
-
Resolution: Fixed
-
Low (View bug fix roadmap)
-
8.15.0
-
None
-
4.3
-
Medium
-
CVE-2021-39124
The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request.
*Affected versions:*
- version < 8.16.0
*Fixed versions:*
- 8.16.0
[JRASERVER-72761] Replay attack via the CSRF failure retry form - CVE-2021-39124
Remote Link | New: This issue links to "Page (Confluence)" [ 689965 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 626685 ] |
CVSS Severity | Original: Low [ 16632 ] | New: Medium [ 16633 ] |
CVSS Score | Original: 3.1 | New: 4.3 |
Remote Link | New: This issue links to "Page (Confluence)" [ 622626 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 618566 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 589045 ] |
CVE ID | New: CVE-2021-39124 |
Security | Original: Atlassian Staff [ 10750 ] |
This issue has been assigned Qualys QID 730196 and a Severity of 3