Atlassian JIRA Server CSRF vulnerability detected port.data-version="7.12.1">

Jeff Kell July 3, 2019

Is there a fix in JIRA to remove the CSRF vulnerability?

3 answers

0 votes
Rafeeq Mohammed (CONT)
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
June 10, 2020

Hi Guys, 

Do you guys know something about whitehat security csrf vulnerability , i am facing issue in deploying it getting "whitelabel error page : Invalid CSRF Token 'null' was found on the request parameter'_csrf' or header 'X-XSRF-TOKEN'."

 

Any help will be appreciated 

 

Thanks

0 votes
Jeff Kell July 5, 2019

Thanks.  We upgraded to 8.0.2 (latest approved so far within our company).  We'll see if the next scan also flags "CSRF" issues.

0 votes
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
July 3, 2019

Which vulnerability?  All we've got there is 7.12.1 which has a number, mostly fixed by "upgrade" as recommended by Atlassian.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events