Description
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cross-Site Request Forgery (CSRF) vulnerability, following an Information Disclosure vulnerability in the referrer headers which discloses a user's CSRF token. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2.
Remediation
References
Related Vulnerabilities
WordPress Plugin NextGEN Smooth Gallery 'galleryID' Parameter SQL Injection (1.2)
WordPress Plugin GigPress Multiple Vulnerabilities (2.3.10)
Joomla Session Fixation Vulnerability (CVE-2007-4188)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-0327)
Jenkins Inadequate Encryption Strength Vulnerability (CVE-2017-2598)