QID 150392
Date Published: 2021-11-24
QID 150392: Atlassian Jira Server Reverse Tabnapping Vulnerability (CVE-2021-39112)
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
The installed version of Jira Atlassian Server allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature.
Affected versions:
before version 8.5.15
from version 8.6.0 before 8.13.7
from version 8.14.0 before 8.17.1
from version 8.18.0 before 8.18.1
Successful exploitation would lead attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability.
Solution
Upgrade the Atlassian Jira to new version.
Vendor References
- JRASERVER-72433 -
jira.atlassian.com/browse/JRASERVER-72433
CVEs related to QID 150392
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72433 |
|