Description
The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via "cookie tossing" a CSRF cookie from a subdomain of a Jira instance.
Remediation
References
Related Vulnerabilities
WordPress Cross-Site Scripting Vulnerability (0.70 - 3.7.11)
Squid Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-18679)
WordPress 5.3.x Multiple Vulnerabilities (5.3 - 5.3.10)
Oracle JRE CVE-2013-5830 Vulnerability (CVE-2013-5830)
WordPress Plugin Add Edit Delete Listing Module SQL Injection (1.0)