QID 730279
Date Published: 2021-11-24
QID 730279: Atlassian Jira Server and Data Center Broken Access Control Vulnerability (JRASERVER-72003)
Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
CVE-2021-39127: Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint via a Broken Access Control vulnerability (BAC) vulnerability.
Affected version:
Atlassian Jira Server and Data Center version prior to 8.5.10
Atlassian Jira Server and Data Center version from 8.6.0 to 8.13.0
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Successful exploitation of this vulnerability will allow anonymous remote attackers to the query component JQL endpoint
Solution
Customers are advised to refer to JRASERVER-72003 for updates pertaining to this vulnerability.
Vendor References
- JRASERVER-72003 -
jira.atlassian.com/browse/JRASERVER-72003
CVEs related to QID 730279
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72003 |
|