Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2019-14998 - Vulnerability Database

Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2019-14998

Medium
Reference: CVE-2019-14998
Title: Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability
Overview:

The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via quotcookie tossingquot a CSRF cookie from a subdomain of a Jira instance.