PT-2019-12976 · Bobronix · Jeditor For Jira

Published

2019-06-21

·

Updated

2019-06-25

·

CVE-2019-12836

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bobronix JEditor for Jira versions prior to 3.0.6
Description The issue allows an attacker to add a URL/Link to an existing issue that can cause forgery of a request to an out-of-origin domain. This may lead to a forged request being invoked in the context of an authenticated user, resulting in the stealing of session tokens and potential account takeover.
Recommendations For versions prior to 3.0.6, update to version 3.0.6 or later to resolve the issue.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12836

Affected Products

Jeditor For Jira