CVE-2018-13402: CSRF
Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1 allow remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via a open redirect vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13402?
CVE-2018-13402 is classified as a medium severity vulnerability affecting specific versions of Atlassian Jira.
How do I fix CVE-2018-13402?
To fix CVE-2018-13402, upgrade Atlassian Jira to the latest version that is not vulnerable.
Which versions are affected by CVE-2018-13402?
CVE-2018-13402 affects Atlassian Jira versions prior to 7.6.9 and versions from 7.7.0 to up to 7.7.5, several other versions up to 7.13.0.
What types of Atlassian Jira products are impacted by CVE-2018-13402?
Both Atlassian Jira and Atlassian Jira Server products are impacted by CVE-2018-13402.
Is CVE-2018-13402 a remote vulnerability?
Yes, CVE-2018-13402 can potentially be exploited remotely.