QID 150379
Date Published: 2021-10-26
QID 150379: Atlassian Jira Server Improper authorization (CVE-2020-4029)
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
The installed version of Jira Atlassian Server allow remote attackers to enumerate project names via an improper authorization vulnerability in the /rest/project-templates/1.0/createshared endpoint API endpoint.
Affected versions:
before version 8.5.5
from 8.6.0 before 8.7.2
from 8.8.0 before 8.8.1
Successful exploitation would lead attackers to enumerate project names, which can help the attacker carry out further attacks and obtain sensitive information.
Solution
Upgrade the Atlassian Jira to new version.
Vendor References
- JRASERVER-70926 -
jira.atlassian.com/browse/JRASERVER-70926
CVEs related to QID 150379
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-70926 |
|