CVE-2019-15002

An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.
References
Link Resource
https://jira.atlassian.com/browse/JRASERVER-67979 Vendor Advisory Issue Tracking
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*

History

30 Jul 2025, 17:20

Type Values Removed Values Added
References () https://jira.atlassian.com/browse/JRASERVER-67979 - () https://jira.atlassian.com/browse/JRASERVER-67979 - Vendor Advisory, Issue Tracking
CPE cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*
First Time Atlassian jira Server
Atlassian jira Data Center
Atlassian

13 Mar 2025, 15:15

Type Values Removed Values Added
CWE CWE-352

28 Feb 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
Summary
  • (es) Existe una vulnerabilidad CSRF explotable en Atlassian Jira, desde las versiones 7.6.4 a 8.1.0. El formulario de inicio de sesión no requiere un token CSRF. Como resultado, un atacante puede iniciar sesión en el sistema con un usuario con una cuenta inesperada.

11 Feb 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 18:15

Updated : 2025-07-30 17:20


NVD link : CVE-2019-15002

Mitre link : CVE-2019-15002

CVE.ORG link : CVE-2019-15002


JSON object : View

Products Affected

atlassian

  • jira_data_center
  • jira_server
CWE
CWE-352

Cross-Site Request Forgery (CSRF)