QID 150435
Date Published: 2021-12-09
QID 150435: Atlassian Jira Server Information Disclosure Vulnerability (JRASERVER-72715)
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
The installed version of Jira Atlassian Server allow authenticated remote attackers to enumerate the keys of private Jira projects via an Information Disclosure vulnerability in the /rest/api/latest/projectvalidate/key endpoint.
Affected versions:
before version 8.5.18
from version 8.6.0 before 8.13.10
from version 8.14.0 before 8.18.2
Successful exploitation would lead attackers to enumerate the keys of private Jira projects, which can help the attacker carry out further attacks and obtain sensitive information.
Solution
Upgrade the Atlassian Jira to new version.
Vendor References
- JRASERVER-72715 -
jira.atlassian.com/browse/JRASERVER-72715
CVEs related to QID 150435
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72715 |
|