Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
Community Members
Community Events
Community Groups


It has been identified that the forms do not have mechanisms to
prevent CSRF attacks, because of this, a malicious user can force the browser to
a victim user to generate and send requests that the application interprets as legitimate
from the victim. A successful CSRF attack can compromise the data of a
end user and through this enter "valid" requests that modify the
behavior of the application in favor of the attacker

We have a lastest versión of crowd 4.1.0 dockerized with mysql database

Thank you.


1 answer

0 votes

Right.  So have you reported this?  Is it possibly fixed in a later version?

It has not been fixed in the latest version, we have reported it

yes, and also in the RelayState parameter, they are lacking the business logic of the anti-CSRF. 

Suggest an answer

Log in or Sign up to answer
Community showcase
Published in Confluence

An update on Confluence Cloud customer feedback – June 2022

Hi everyone, We’re always looking at how to improve Confluence and customer feedback plays an important role in making sure we're investing in the areas that will bring the most value to the most c...

170 views 1 3
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you