•  
      request #46389 Missing CSRF protection in the Overview inconsistent items
    Infos
    #46389
    Joris MASSON (jmasson)
    2026-02-02 16:21
    2026-01-20 14:30
    48111
    Details
    Missing CSRF protection in the Overview inconsistent items

    In the Backlog service, when you browse a milestone (for example : Release, Sprint), by default you land on a tab called "Overview" that lists items planned in the milestone. Some items can be in an inconsistent state, and the button to repair those inconsistent items is not protected against CSRFs.

    Impact

    An attacker could use this vulnerability to trick victims into repairing inconsistent items (creating artifact links from the release).
    CVSSv3.1 score: 4.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L)

    References

    CWE 352
    Cross-Site Request Forgery - OWASP
    CVE-2026-24007

    Agile Dashboard
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Joris MASSON (jmasson)
    Closed
    2026-01-20
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2026-01-22 09:16

    CVE-2026-24007 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2026-01-20 15:30
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes