PT-2019-12398 · Atlassian · Jira

Publicado

2019-08-23

·

Atualizado

2022-03-25

·

CVE-2019-11588

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Jira versions prior to 7.13.6 Jira versions 8.0.0 through 8.2.3 Jira versions 8.3.0 through 8.3.2
Description The issue allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability. This is related to the doGarbageCollection method in the ViewSystemInfo class.
Recommendations For versions prior to 7.13.6, update to version 7.13.6 or later. For versions 8.0.0 through 8.2.3, update to version 8.2.3 or later. For versions 8.3.0 through 8.3.2, update to version 8.3.2 or later.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11588

Produtos afetados

Jira