PT-2019-12976 · Bobronix · Jeditor For Jira
Published
2019-06-21
·
Updated
2019-06-25
·
CVE-2019-12836
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bobronix JEditor for Jira versions prior to 3.0.6
Description
The issue allows an attacker to add a URL/Link to an existing issue that can cause forgery of a request to an out-of-origin domain. This may lead to a forged request being invoked in the context of an authenticated user, resulting in the stealing of session tokens and potential account takeover.
Recommendations
For versions prior to 3.0.6, update to version 3.0.6 or later to resolve the issue.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jeditor For Jira