Uploaded image for project: 'Xporter for Jira'
  1. Xporter for Jira
  2. XPORTER-3179

Site-wide CSRF on Xporter actions and pages

    XporterXMLWordPrintable

Details

    • OK

    Description

      Site-wide CSRF on admin settings page:

      ​1. Login to your Jira instance
      ​2. Click on the gear icon top right corner, and select Manage Apps
      3. ​In the left menu, click on Global Settings
      ​4. Change any of the settings and notice that no CSRF protection is in place.
      ​5. Check any POST request to /secure/admin/views/Xporter* and notice that no CSRF protection is in place.

      All the actions must be reviewed including action regarding Xporter Project level configuration.

      Attachments

        Issue Links

          Activity

            People

              rmbr Rui Rodrigues
              rmbr Rui Rodrigues
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - 0 minutes
                  0m
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 1 week, 10 minutes
                  1w 10m