QID 150683
Date Published: 2023-05-12
QID 150683: Atlassian Jira Unauthorized Access to Resolutions
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
Atlassian Jira Server has a security vulnerability that allows remote attackers to access "resolutions" through the /rest/api/2/resolution endpoint.
QID Detection Logic (Unauthenticated) :
This QID sends a HTTP GET request to "/rest/api/2/resolution" endpoint and based on the response confirms if the target is vulnerable.
This vulnerability potentially exposes sensitive data and compromises the security of the affected Jira Server instance.
Solution
Block the unauthenticated access to this particular URL */rest/api/2/resolution at the network level. For more information regarding this vulnerability please refer Restrict unauthenticated access for Jira endpoints.
Vendor References
CVEs related to QID 150683
Software Advisories
| Advisory ID | Software | Component | Link |
|---|