Atlassian Jira Cross-Site Request Forgery Vulnerability in Login Authentication

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in Atlassian Jira versions 7.6.4 prior to 8.1.0. The issue arises because the login form does not require a CSRF token, allowing an attacker to log a user into the system under an unexpected account.

Impact

Exploitation of this vulnerability allows for unauthorized account login, potentially leading to unauthorized actions being performed on behalf of the user.

Remediation

Users can upgrade to Jira version 8.0.0 or later, where this vulnerability has been fixed. Instructions for upgrading can be found in the Jira 8.14.x upgrade notes.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
1.3
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.