{"api_version":"1","generated_at":"2026-07-24T20:49:53+00:00","cve":"CVE-2019-11587","urls":{"html":"https://cve.report/CVE-2019-11587","api":"https://cve.report/api/cve/CVE-2019-11587.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-11587","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-11587"},"summary":{"title":"CVE-2019-11587","description":"Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).","state":"PUBLIC","assigner":"security@atlassian.com","published_at":"2019-08-23 14:15:00","updated_at":"2022-03-25 17:20:00"},"problem_types":["CWE-352"],"metrics":[],"references":[{"url":"https://jira.atlassian.com/browse/JRASERVER-69782","name":"https://jira.atlassian.com/browse/JRASERVER-69782","refsource":"MISC","tags":["Issue Tracking","Vendor Advisory"],"title":"[JRASERVER-69782] The ViewLogging class exposed various resources that were vulnerable to CSRF - CVE-2019-11587 - Create and track feature requests for Atlassian products.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-11587","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11587","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"11587","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"atlassian","cpe5":"jira","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"11587","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"atlassian","cpe5":"jira","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"11587","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"atlassian","cpe5":"jira_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@atlassian.com","DATE_PUBLIC":"2019-08-13T00:00:00","ID":"CVE-2019-11587","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Jira","version":{"version_data":[{"version_value":"7.13.6","version_affected":"<"},{"version_value":"8.0.0","version_affected":">="},{"version_value":"8.2.3","version_affected":"<"},{"version_value":"8.3.0","version_affected":">="},{"version_value":"8.3.2","version_affected":"<"}]}}]},"vendor_name":"Atlassian"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Cross-Site Request Forgery (CSRF)"}]}]},"references":{"reference_data":[{"url":"https://jira.atlassian.com/browse/JRASERVER-69782","refsource":"MISC","name":"https://jira.atlassian.com/browse/JRASERVER-69782"}]}},"nvd":{"publishedDate":"2019-08-23 14:15:00","lastModifiedDate":"2022-03-25 17:20:00","problem_types":["CWE-352"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:*","versionEndExcluding":"7.13.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"8.3.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"8.2.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"11587","Ordinal":"149886","Title":"CVE-2019-11587","CVE":"CVE-2019-11587","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"11587","Ordinal":"1","NoteData":"Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).","Type":"Description","Title":null},{"CveYear":"2019","CveId":"11587","Ordinal":"2","NoteData":"2019-08-23","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"11587","Ordinal":"3","NoteData":"2019-08-23","Type":"Other","Title":"Modified"}]}}}