CVE-2021-39124
CVE-2021-39124
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
14 Sep 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →