QID 730149

Date Published: 2021-08-11

QID 730149: Atlassian Jira Data Center And Jira Service Management Missing Authorization Vulnerability (JRASERVER-72666)

Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.

Affected by below vulnerability:
CVE-2020-36239: Missing Authentication for Ehcache RMI

Affected version:
The versions of Jira Data Center, Jira Core Data Center, and Jira Software Data Center affected by this vulnerability are:
From version 6.3.0 before 8.5.16
From version 8.6.0 before 8.13.8
From version 8.14.0 before 8.17.0

The versions of Jira Service Management Data Center affected by this vulnerability are:
From version 2.0.2 before 4.5.16
From version 4.6.0 before 4.13.8
From version 4.14.0 before 4.17.0

QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.

Successful exploitation of this vulnerability may allows could execute arbitrary code of their choice in Jira through deserialization due to a missing authentication vulnerability.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer JRASERVER-72666 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 730149

    Software Advisories
    Advisory ID Software Component Link
    JRASERVER-72566 URL Logo jira.atlassian.com/browse/JRASERVER-72566