Back to search
CVE-2008-6531
Published: Mar 26, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
The WebWork 1 web application framework in Atlassian JIRA before 3.13.2 allows remote attackers to invoke exposed public JIRA methods via a crafted URL that is dynamically transformed into method calls, aka "WebWork 1 Parameter Injection Hole."
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
33084
third-party-advisory
x_refsource_SECUNIA
52707
vdb-entry
x_refsource_OSVDB
32746
vdb-entry
x_refsource_BID
jira-webwork1-security-bypass(47211)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now