Medium severity4.3NVD Advisory· Published Feb 11, 2025· Updated Jun 17, 2026
CVE-2019-15002
CVE-2019-15002
Description
An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*range: >=7.6.4,<=8.1.0
- (no CPE)range: unspecified
- Range: unspecified
Patches
Vulnerability mechanics
References
1- jira.atlassian.com/browse/JRASERVER-67979nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.