Atlassian JIRA Multiple Open Redirect and Access Bypass Vulnerabilities
BID:105751
CVE-2018-13400 | CVE-2018-13401 | CVE-2018-13402 |Info
Atlassian JIRA Multiple Open Redirect and Access Bypass Vulnerabilities
| Bugtraq ID: | 105751 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-13400 CVE-2018-13401 CVE-2018-13402 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 23 2018 12:00AM |
| Updated: | Oct 23 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Atlassian JIRA 7.13 Atlassian JIRA 7.12.2 Atlassian JIRA 7.12 Atlassian JIRA 7.11.2 Atlassian JIRA 7.11.1 Atlassian JIRA 7.11 Atlassian JIRA 7.10.2 Atlassian JIRA 7.10.1 Atlassian JIRA 7.10 Atlassian JIRA 7.9.2 Atlassian JIRA 7.9.1 Atlassian JIRA 7.9 Atlassian JIRA 7.8.4 Atlassian JIRA 7.8.3 Atlassian JIRA 7.8.1 Atlassian JIRA 7.8 Atlassian JIRA 7.7.4 Atlassian JIRA 7.7.3 Atlassian JIRA 7.7 Atlassian JIRA 7.6.8 Atlassian JIRA 7.6.7 Atlassian JIRA 7.6.6 Atlassian JIRA 7.6.5 Atlassian JIRA 7.6.3 Atlassian JIRA 7.6.2 Atlassian JIRA 7.5.3 Atlassian JIRA 7.4.4 Atlassian JIRA 7.4.2 Atlassian JIRA 7.3 Atlassian JIRA 7.2.12 Atlassian JIRA 7.2.1 Atlassian JIRA 7.2 Atlassian JIRA 7.1.10 Atlassian JIRA 7.1.9 Atlassian JIRA 7.1.8 Atlassian JIRA 7.1.7 Atlassian JIRA 7.1.6 Atlassian JIRA 7.1.5 Atlassian JIRA 7.1.4 Atlassian JIRA 7.1.2 Atlassian JIRA 7.1.1 Atlassian JIRA 7.1 Atlassian JIRA 7.0.11 Atlassian JIRA 7.0.4 Atlassian JIRA 7.0.3 Atlassian JIRA 3.7.4 Atlassian JIRA 3.7.3 Atlassian JIRA 3.7.1 Atlassian JIRA 7.8.2 Atlassian JIRA 7.6.1 Atlassian JIRA 7.6.0 Atlassian JIRA 7.2.2 Atlassian JIRA 3.7.2 |
| Not Vulnerable: |
Atlassian JIRA 7.13.1 Atlassian JIRA 7.12.3 Atlassian JIRA 7.11.3 Atlassian JIRA 7.10.3 Atlassian JIRA 7.9.3 Atlassian JIRA 7.8.5 Atlassian JIRA 7.7.5 Atlassian JIRA 7.6.9 |
Discussion
Atlassian JIRA Multiple Open Redirect and Access Bypass Vulnerabilities
Atlassian JIRA is prone to the following multiple security vulnerabilities:
1. An access-bypass Vulnerability
2. Multiple open-redirection Vulnerabilities
Exploiting these issues will allow an attacker to bypass security restrictions or construct a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
JIRA prior to 7.6.9, 7.7.0 through 7.7.4, 7.8.0 through 7.8.4, 7.9.0 through 7.9.2, 7.10.0 through 7.10.2, 7.11.0 through 7.11.2, 7.12.0 through 7.12.2, and prior to 7.13.1 are vulnerable.
Atlassian JIRA is prone to the following multiple security vulnerabilities:
1. An access-bypass Vulnerability
2. Multiple open-redirection Vulnerabilities
Exploiting these issues will allow an attacker to bypass security restrictions or construct a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
JIRA prior to 7.6.9, 7.7.0 through 7.7.4, 7.8.0 through 7.8.4, 7.9.0 through 7.9.2, 7.10.0 through 7.10.2, 7.11.0 through 7.11.2, 7.12.0 through 7.12.2, and prior to 7.13.1 are vulnerable.
Solution / Fix
Atlassian JIRA Multiple Open Redirect and Access Bypass Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Atlassian JIRA Multiple Open Redirect and Access Bypass Vulnerabilities
References:
References: