QID 150674
Date Published: 2023-04-26
QID 150674: Atlassian Jira Unauthorized Access to Installed Gadgets
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
Atlassian Jira Server has a security vulnerability that allows remote attackers to access installed gadgets through the /rest/config/1.0/directory endpoint. Gadgets are small web applications that can be installed on Jira dashboards to provide additional functionality and integration with other systems.
QID Detection Logic (Unauthenticated) :
This QID sends a HTTP GET request to "/rest/config/1.0/directory" endpoint and based on the response confirms if the target is vulnerable.
Vulnerability could potentially allow an attacker to obtain sensitive information or perform unauthorized actions by exploiting the gadgets installed on Jira Server.
CVEs related to QID 150674
| Advisory ID | Software | Component | Link |
|---|