QID 730113
Date Published: 2021-06-16
QID 730113: Atlassian Jira Server Missing Permissions Check Vulnerability (JRASERVER-69792)
Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
Affected by below vulnerability:
CVE-2019-14995: Disclosure of issue key validity and issue attachment names in the render api resource.
Affected version:
Atlassian Jira Server version prior to 7.13.13
Atlassian Jira Server version from 8.0.0 and prior to 8.4.0
Fixed Versions:
Atlassian Jira Server 8.4.0 and 7.13.13
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.
Solution
Customers are advised to refer JRASERVER-69792 for updates pertaining to this vulnerability.
Vendor References
- JRASERVER-69792 -
jira.atlassian.com/browse/JRASERVER-69792
CVEs related to QID 730113
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-69792 |
|