Atlassian JIRA Server CSRF vulnerability detected port.data-version="7.12.1">

Jeff Kell July 3, 2019

Is there a fix in JIRA to remove the CSRF vulnerability?

3 answers

0 votes
Rafeeq Mohammed (CONT) June 10, 2020

Hi Guys, 

Do you guys know something about whitehat security csrf vulnerability , i am facing issue in deploying it getting "whitelabel error page : Invalid CSRF Token 'null' was found on the request parameter'_csrf' or header 'X-XSRF-TOKEN'."

 

Any help will be appreciated 

 

Thanks

0 votes
Jeff Kell July 5, 2019

Thanks.  We upgraded to 8.0.2 (latest approved so far within our company).  We'll see if the next scan also flags "CSRF" issues.

0 votes
Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
July 3, 2019

Which vulnerability?  All we've got there is 7.12.1 which has a number, mostly fixed by "upgrade" as recommended by Atlassian.

Suggest an answer

Log in or Sign up to answer