Our security department has scanned our Jira (v7.4.2#74004-sha1:586975d) using an IBM tool called Appscan. It reported a possible vulnerability. I have to prepare a response to indicate if this is a known problem and when or if it will be fixed. Any assistance would be appreciated.
Text from the report follows:
Cross-Site Request Forgery. It may be possible to steal or manipulate customer session and cookies, which might be used to impersonate a legitimate user, allowing the hacker to view or alter user records, and to perform transactions as that user. The test result seems to indicate a vulnerability because the test response is identical to the original response, indicating that the Cross Site Request Forgery attempt was successful, even though it included a fictive “Referer” header.
Recommendation: Validate the value of the "Referer" header, and use a one-time-nonce for each submitted form