PT-2019-12976 · Bobronix · Jeditor For Jira
Publicado
2019-06-21
·
Atualizado
2019-06-25
·
CVE-2019-12836
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bobronix JEditor for Jira versions prior to 3.0.6
Description
The issue allows an attacker to add a URL/Link to an existing issue that can cause forgery of a request to an out-of-origin domain. This may lead to a forged request being invoked in the context of an authenticated user, resulting in the stealing of session tokens and potential account takeover.
Recommendations
For versions prior to 3.0.6, update to version 3.0.6 or later to resolve the issue.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jeditor For Jira