QID 150678
Date Published: 2023-04-26
QID 150678: Atlassian Jira Unauthorized Access to Admin Projects
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
Atlassian Jira Server has a security vulnerability that allows remote attackers to access Admin Projects through the /rest/menu/latest/admin endpoint.
QID Detection Logic (Unauthenticated) :
This QID sends a HTTP GET request to "/rest/menu/latest/admin" endpoint and based on the response confirms if the target is vulnerable.
This vulnerability potentially exposes sensitive data and compromises the security of the affected Jira Server instance.
Solution
Block the unauthenticated access to this particular URL */rest/menu/latest/admin at the network level. For more information regarding this vulnerability please refer JRASERVER-64963.
Vendor References
CVEs related to QID 150678
Software Advisories
| Advisory ID | Software | Component | Link |
|---|