Back

MEDIUM

An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0

Published Feb 11, 2025

Description

An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner atlassian
Published Feb 11, 2025
Updated Mar 13, 2025
Reserved Aug 13, 2019
CISA Vulnrichment
Updated Feb 28, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a