The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1 allows remote attackers to obtain a user's Cross-site request forgery (CSRF) token through an open redirect vulnerability.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: atlassian
Published: 2018-10-23T14:00:00Z
Updated: 2024-09-17T03:13:21.525Z
Reserved: 2018-07-06T00:00:00
Link: CVE-2018-13401
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-10-23T13:29:03.040
Modified: 2024-11-21T03:47:01.970
Link: CVE-2018-13401
Redhat
No data.