Looking for the vulnerability index of Invicti's legacy products?
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-14998) - Vulnerability Database

Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-14998)

Description

The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via "cookie tossing" a CSRF cookie from a subdomain of a Jira instance.

References

Related Vulnerabilities