Uploaded image for project: 'Xray for Jira'
  1. Xray for Jira
  2. XRAY-4740

Site-wide CSRF protection

    XporterXMLWordPrintable

Details

    • OK

    Description

      Site-wide CSRF on admin settings page:

       

      Endpoints confirmed too be vulnerable:
      POST /secure/admin/views/XrayIssueTypeMappingConfiguration!save.jspa
      POST /secure/admin/views/XrayRequirementCoverageConfiguration!save.jspa
      POST /secure/admin/views/XrayTestStatusConfiguration!save.jspa
      POST /secure/admin/views/XrayTestStatusConfiguration!delete.jspa
      POST /secure/admin/views/XrayTestStatusConfiguration!savePrefs.jspa
      POST /secure/admin/views/XrayColumnLayoutConfiguration!save.jspa
      POST /secure/admin/views/XrayCustomFieldConfiguration!save.jspa

      Attachments

        Activity

          People

            Unassigned Unassigned
            hslb Hugo Braz [X] (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - 0 minutes
                0m
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 4 weeks, 2 days, 5 hours
                4w 2d 5h