GH Webwork actions are vulnerable to XSRF.

XMLWordPrintable

      GHCreateNewIssue.jspa is not protected against XSRF attacks.
      Impact: It is possible for an attacker to make a victim create new issues on the victim's JIRA instance through this bug in GHCreateNewIssue.jspa.

              Assignee:
              Michael Tokar
              Reporter:
              David Black
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: