Back to search
CVE-2019-14998
Published: Sep 11, 2019
Modified: Sep 16, 2024
PUBLISHED
Description
The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via "cookie tossing" a CSRF cookie from a subdomain of a Jira instance.
| Vendor | Product | Versions |
|---|---|---|
Atlassian | Jira | affected unspecified - < 8.4.0 |
References
https://jira.atlassian.com/browse/JRASERVER-69791
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now