CVE-2016-4319: CSRF
Published Apr 10, 2017
·Updated
Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.
Affected Software
1 affected component
Atlassian Jira<=7.1.8
Event History
Apr 10, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-4319?
CVE-2016-4319 has a medium severity rating due to its potential impact on auditing and settings.
2
How do I fix CVE-2016-4319?
To fix CVE-2016-4319, upgrade Atlassian JIRA Server to version 7.1.9 or later.
3
Which versions of Atlassian JIRA are affected by CVE-2016-4319?
CVE-2016-4319 affects Atlassian JIRA Server versions prior to 7.1.9.
4
What type of vulnerability is CVE-2016-4319?
CVE-2016-4319 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Is there a workaround for CVE-2016-4319?
There is no official workaround for CVE-2016-4319; upgrading is the recommended solution.