CVE-2017-16862: Atlassian Jira

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability.

Affected products

  • Atlassian Jira: before 7.6.2 (fixed in 7.6.2)

Published 2018-01-12. Last modified 2026-06-17.