---
title: "Comala Boards Security Advisory 2020-11-12"
canonical: "https://support.appfire.com/space/CBCSL/641898383/Comala%20Boards%20Security%20Advisory%202020-11-12"
format: markdown
---
> Macro (aura-html)

This advisory discloses a security vulnerability found and fixed in Comala Boards.  We recommend upgrading Comala Boards to the latest supported version.

## Affected Versions

The vulnerability affects **Comala Boards 2.3.3 and lower versions**

The **2.3.4 release contains a fix** for the issue mentioned below.

## Cross-Site Request Forgery Vulnerability

### Severity

We rate the severity of these issues as **Medium** according to the published [Atlassian Security Levels](https://www.atlassian.com/security/security-severity-levels).

<span style="color: #000000">We have ranked the vulnerability as </span><span style="color: #000000">**Medium**</span><span style="color: #000000"> because</span>

- Cross-Site Request Forgery (CSRF) vulnerability affecting only Comala Boards<span style="color: #000000">**-**</span>related actions

This is an independent assessment and you should evaluate its applicability to your IT environment.

### Description

<span style="color: #323639">Authenticated users with enough permissions to perform certain Comala Boards actions could be tricked into unwillingly performing them.</span>

### Risk Mitigation

> 📝 Sites running Comala Boards 2.3.3 or lower are recommended to upgrade to Comala Boards 2.3.4.