CVE Database
/

CVE-2019-15002

Back to search

CVE-2019-15002

Published: Feb 11, 2025

Modified: Mar 13, 2025

PUBLISHED

Description

An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.

VendorProductVersions

Atlassian

Jira Server

unaffected
unspecified - < 7.6.4
affected
unspecified - < 8.1.0

Atlassian

Jira Data Center

unaffected
unspecified - < 7.6.4
affected
unspecified - < 8.1.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now