QID 730181
Date Published: 2021-09-06
QID 730181: Atlassian Jira Server and Data Center Broken Access Control Vulnerability (JRASERVER-72573)
Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
CVE-2021-39113: Atlassian Jira Server and Data Center allow an anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature.
Affected version:
Atlassian Jira Server and Data Center version prior to 8.13.9
Atlassian Jira Server and Data Center version from 8.14.0 prior to 8.18.0
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Successful exploitation of this vulnerability may allow an anonymous remote attackers to continue to view cached content even after losing permissions.
- JRASERVER-72573 -
jira.atlassian.com/browse/JRASERVER-72573
CVEs related to QID 730181
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72573 |
|