Atlassian Jira
cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*, +1 more
- >= 7.6.4, <= 8.1.0
A cross-site request forgery (CSRF) vulnerability has been identified in Atlassian Jira versions 7.6.4 prior to 8.1.0. The issue arises because the login form does not require a CSRF token, allowing an attacker to log a user into the system under an unexpected account.
Exploitation of this vulnerability allows for unauthorized account login, potentially leading to unauthorized actions being performed on behalf of the user.
Users can upgrade to Jira version 8.0.0 or later, where this vulnerability has been fixed. Instructions for upgrading can be found in the Jira 8.14.x upgrade notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.