QID 150468
Date Published: 2022-02-09
QID 150468: Atlassian Jira Server Broken Access Control Vulnerability (JRASERVER-72940)
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
The installed version of Jira Atlassian Server allow low privileged user to edit the File Replication settings via a Broken Access Control vulnerability in the ReplicationSettings!default.jspa endpoint.
Affected versions:
before version 8.6.0
from version 8.7.0 before 8.13.12
from version 8.14.0 before 8.20.1
Successful exploitation of this vulnerability may allow non-administrators can edit the File Replication settings
Solution
Upgrade the Atlassian Jira to new version.
Vendor References
- JRASERVER-72940 -
jira.atlassian.com/browse/JRASERVER-72940
CVEs related to QID 150468
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72940 |
|