QID 730032

Date Published: 2021-04-06

QID 730032: Atlassian Jira Server And Data Center Improper Authentication Vulnerability(JRASERVER-72029)

Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.

CVE-2021-26070: Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource
Affected version:
Atlassian Jira Server and Data Center version prior to 8.13.3
Atlassian Jira Server and Data Center version from 8.14.0 and before 8.14.1

QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.

Successful exploit could allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Customers are advised to refer to JJRASERVER-72029 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 730032

    Software Advisories
    Advisory ID Software Component Link
    JRASERVER-72029 URL Logo jira.atlassian.com/browse/JRASERVER-72029