QID 150487
Date Published: 2022-03-16
QID 150487: Atlassian Jira Server Multiple Vulnerabilities (JRASERVER-73071,JRASERVER-73138)
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
Multiple Vulnerabilities are identified in Atlassian Jira Server:
CVE-2021-43946 : The installed version of Jira Atlassian Server using the Jira Service Management addon allow remote attackers to add administrator groups to filter subscriptions via a Broken Access Control vulnerability in the /secure/EditSubscription.jspa endpoint.
CVE-2021-43952 : The installed version of Jira Atlassian Server using the Jira Service Management addon allow remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint.
Affected version:
before version 8.21.0
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Successful exploitation of these vulnerabilities may allow remote attacker to impact the application's confidentiality, integrity and availability via Broken Authentication and Cross-Site Request Forgery (CSRF) vulnerability.
- JRASERVER-73071 -
jira.atlassian.com/browse/JRASERVER-73071 - JRASERVER-73138 -
jira.atlassian.com/browse/JRASERVER-73138
CVEs related to QID 150487
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-73071 |
|
||
| JRASERVER-73138 |
|