QID 150468

Date Published: 2022-02-09

QID 150468: Atlassian Jira Server Broken Access Control Vulnerability (JRASERVER-72940)

Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.

The installed version of Jira Atlassian Server allow low privileged user to edit the File Replication settings via a Broken Access Control vulnerability in the ReplicationSettings!default.jspa endpoint.

Affected versions:
before version 8.6.0
from version 8.7.0 before 8.13.12
from version 8.14.0 before 8.20.1

Successful exploitation of this vulnerability may allow non-administrators can edit the File Replication settings

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Upgrade the Atlassian Jira to new version.
    Vendor References

    CVEs related to QID 150468

    Software Advisories
    Advisory ID Software Component Link
    JRASERVER-72940 URL Logo jira.atlassian.com/browse/JRASERVER-72940