Org Web Adapter

pages/eng_10078_csrf_in_account_security_settings_bug.org

ID
fb6d1d0e-b04f-4f11-8cd3-f399d57dff06
ROAM_ALIASES
ENG-10078

ENG-10078 - CSRF in account security settings bug

- source :: https://15five-dev.atlassian.net/browse/ENG-10078

- tags :: Jira 15Five Security

Description

See attached PDF of vulnerability.

Affects MFA (Account and user administration)

Fix needs to be on staging by 6/20/2020 to be ready for remediation testing.

May 27 discussion: Investigate whether CSRF is enabled on the MFA endpoint. Spike to commence ASAP.