First published: Thu Jan 18 2018(Updated: )
The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian JIRA | <7.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18033 has been classified as a medium severity vulnerability due to its potential for unauthorized project creation and interference with system imports.
To fix CVE-2017-18033, upgrade Atlassian Jira to version 7.6.1 or later which contains the necessary patches.
CVE-2017-18033 enables remote attackers to perform Cross-site request forgery (CSRF) attacks that can create new projects and abort imports.
Atlassian Jira versions prior to 7.6.1 are affected by CVE-2017-18033.
You can check your Jira logs for unauthorized project creation or import aborts as potential indicators of exploitation of CVE-2017-18033.