QID 150380
Date Published: 2021-11-09
QID 150380: Atlassian Jira Server Man In The Middle (CVE-2020-14168)
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
The installed version of Jira Atlassian Server allow remote attackers to access outgoing emails between a Jira instance and the SMTP server via man-in-the-middle (MITM) vulnerability.
Affected versions:
before version 7.13.16
from 8.5.0 before 8.5.7
from 8.8.0 before 8.8.2
from 8.9.0 before 8.9.1
Successful exploitation would lead attackers to access outgoing emails, which can help the attacker carry out further attacks and obtain sensitive information.
Solution
Upgrade the Atlassian Jira to new version.
Vendor References
- JRASERVER-71198 -
jira.atlassian.com/browse/JRASERVER-71198
CVEs related to QID 150380
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-71198 |
|