QID 730252
Date Published: 2021-11-15
QID 730252: Atlassian Jira Server and Data Center Improper Authentication Vulnerability (JRASERVER-72801)
Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
CVE-2021-41312:Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint.
Affected version:
Atlassian Jira Server and Data Center version prior to 8.19.1
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Successful exploitation of this vulnerability allows a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects,
- JRASERVER-72801 -
jira.atlassian.com/browse/JRASERVER-72801
CVEs related to QID 730252
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72801 |
|