QID 730248

Date Published: 2021-11-17

QID 730248: Atlassian Jira Server and Data Center Broken Access Control Vulnerability (JRASERVER-72940)

Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.

CVE-2021-41308: Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Replication settings via a Broken Access Control vulnerability in the `ReplicationSettings!default.jspa` endpoint.

Affected version:
Atlassian Jira Server and Data Center version prior to 8.6.0
Atlassian Jira Server and Data Center version between 8.7.0 (inclusive) and 8.13.12

Atlassian Jira Server and Data Center version between 8.14.0 (inclusive) and 8.20.1

QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.

Successful exploitation of this vulnerability may allow non-administrators can edit the File Replication settings

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to refer to JRASERVER-72940 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 730248

    Software Advisories
    Advisory ID Software Component Link
    JRASERVER-72940 URL Logo jira.atlassian.com/browse/JRASERVER-72940