QID 150393
Date Published: 2021-11-24
QID 150393: Atlassian Jira Server Broken Access Control Vulnerability in the Allowlist Feature (CVE-2021-39113)
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
The installed version of Jira Atlassian Server allow remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature.
Affected versions:
before version 8.13.9
from version 8.14.0 before 8.18.0
Successful exploitation would lead attackers to continue to view cached content even after losing permissions.
Solution
Upgrade the Atlassian Jira to new version.
Vendor References
- JRASERVER-72573 -
jira.atlassian.com/browse/JRASERVER-72573
CVEs related to QID 150393
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72573 |
|