QID 730173
Date Published: 2021-09-01
QID 730173: Atlassian Jira Server And Data Center Reverse Tabnapping Vulnerability (JRASERVER-72433)
Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
CVE-2021-39112: Allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature.
Affected version:
Atlassian Jira Server and Data Center version prior to 8.5.15
Atlassian Jira Server and Data Center version from 8.6.0 prior to 8.13.7
Atlassian Jira Server and Data Center version from 8.14.0 prior to 8.17.1
Atlassian Jira Server and Data Center version from 8.18.0 prior to 8.18.1
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Successful exploitation of this vulnerability may allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability.
- JRASERVER-72433 -
jira.atlassian.com/browse/JRASERVER-72433
CVEs related to QID 730173
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72433 |
|