Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1 allow remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via a open redirect vulnerability.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: atlassian
Published: 2018-10-23T14:00:00Z
Updated: 2024-09-16T17:52:50.468Z
Reserved: 2018-07-06T00:00:00
Link: CVE-2018-13402
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-10-23T13:29:03.117
Modified: 2024-11-21T03:47:02.103
Link: CVE-2018-13402
Redhat
No data.