QID 150512

Date Published: 2022-05-11

QID 150512: Atlassian Jira Server Broken Authentication vulnerability (JRASERVER-72029)

Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.

The installed version of Jira Atlassian Server allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource.

Affected version:
before version 8.13.3
from version 8.14.0 before 8.14.1

QID Detection Logic:(Unauthenticated):
It checks for vulnerable version of Atlassian Jira Server.

Successful exploit could allow remote attackers to evade behind-the-firewall protection of app-linked resources.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Upgrade the Atlassian Jira to new version.
    Vendor References

    CVEs related to QID 150512

    Software Advisories
    Advisory ID Software Component Link
    JRASERVER-72029 URL Logo jira.atlassian.com/browse/JRASERVER-72029