Description
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cross-Site Request Forgery (CSRF) vulnerability, following an Information Disclosure vulnerability in the referrer headers which discloses a user's CSRF token. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2.
Remediation
References
Related Vulnerabilities
Python Data Processing Errors Vulnerability (CVE-2013-7440)
Ruby on Rails 7PK - Security Features Vulnerability (CVE-2015-7576)
WordPress Plugin Greenshift-animation and page builder blocks Cross-Site Scripting (4.9.9)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2022-2986)
Apache HTTP Server Uncontrolled Resource Consumption Vulnerability (CVE-2009-1891)