Description
The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via "cookie tossing" a CSRF cookie from a subdomain of a Jira instance.
Remediation
References
Related Vulnerabilities
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-35152)
SugarCRM Improper Input Validation Vulnerability (CVE-2012-0694)
WordPress Plugin WooCommerce Arbitrary File Download (3.4.5)
Jetty Weak Authentication Vulnerability (CVE-2023-41900)
WordPress Plugin Your Text Manager Cross-Site Scripting (0.3.0)