CVE-2019-14998: CSRF
Published Sep 11, 2019
·Updated
The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via "cookie tossing" a CSRF cookie from a subdomain of a Jira instance.
Affected Software
1 affected component
Atlassian Jira Server>=7.4.0<8.4.0
Event History
Sep 11, 2019
CVE Published
via MITRE·01:56 PM
Data Sourced
via MITRE·01:56 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-14998?
CVE-2019-14998 has been classified as a high severity vulnerability due to its potential to allow Cross-Site Request Forgery attacks.
2
How do I fix CVE-2019-14998?
To fix CVE-2019-14998, upgrade your Jira Server to version 8.4.0 or later.
3
What is the vulnerability type of CVE-2019-14998?
CVE-2019-14998 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
4
Which versions of Jira are affected by CVE-2019-14998?
Jira Server versions from 7.4.0 to below 8.4.0 are affected by CVE-2019-14998.
5
Can CVE-2019-14998 be exploited remotely?
Yes, CVE-2019-14998 can be exploited remotely by attackers to bypass CSRF protection.