CVE-2019-15002: CSRF
Published Feb 11, 2025
·Updated
An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.
Affected Software
3 affected components
Atlassian Jira>=7.6.4<=8.1.0
Atlassian Jira Data Center>=7.6.4<=8.1.0
Atlassian Jira Server>=7.6.4<=8.1.0
Event History
Feb 11, 2025
CVE Published
via MITRE·05:24 PM
Data Sourced
via MITRE·05:24 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-15002?
CVE-2019-15002 is classified as a critical severity vulnerability due to its ability to bypass authentication.
2
How do I fix CVE-2019-15002?
To fix CVE-2019-15002, upgrade Atlassian Jira to a version above 8.1.0.
3
What versions of Atlassian Jira are affected by CVE-2019-15002?
CVE-2019-15002 affects Atlassian Jira versions from 7.6.4 to 8.1.0.
4
What type of vulnerability is CVE-2019-15002?
CVE-2019-15002 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2019-15002 be exploited remotely?
Yes, CVE-2019-15002 can be exploited remotely, allowing attackers to authenticate as other users.