QID 730196

Date Published: 2021-09-20

QID 730196: Atlassian Jira Server and Data Center Multiple Security Vulnerabilities (JRASERVER-72237, JRASERVER-72761)

Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.

CVE-2021-39123: Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the /rest/gadget/1.0/createdVsResolved/generate endpoint.
CVE-2021-39124: The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request.

Affected version:
Atlassian Jira Server and Data Center prior to 8.16.0

QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.

Successful exploitation of these vulnerabilities may allow remote attacker to impact the application's availability via a Denial of Service (DoS) vulnerability or trick a user into retrying a request to bypass CSRF protection.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to JRASERVER-72237, JRASERVER-72761 for updates pertaining to this vulnerability.

    CVEs related to QID 730196

    Software Advisories
    Advisory ID Software Component Link
    JRASERVER-72237 URL Logo jira.atlassian.com/browse/JRASERVER-72237
    JRASERVER-72761 URL Logo jira.atlassian.com/browse/JRASERVER-72761