QID 150479
Date Published: 2022-03-08
QID 150479: Atlassian Jira Server Improper Authentication Vulnerability (JRASERVER-72801)
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
The installed version of Jira Atlassian Server allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint.
Affected versions:
before version 8.19.1
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Successful exploitation of this vulnerability allows a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects,
- JRASERVER-72801 -
jira.atlassian.com/browse/JRASERVER-72801
CVEs related to QID 150479
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72801 |
|