Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).
2019-08-23T14:15:11.047
2024-11-21T04:21:23.633
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | atlassian | jira | < 7.13.6 | Yes |
Application | atlassian | jira_server | < 8.2.3 | Yes |
Application | atlassian | jira_server | < 8.3.2 | Yes |