CVE-2019-15002: Atlassian Jira Data Center

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.

Affected products

  • Atlassian Jira Data Center: from 7.6.4, up to and including 8.1.0
  • Atlassian Jira Server: from 7.6.4, up to and including 8.1.0

Published 2025-02-11. Last modified 2026-06-17.