QID 730296

Date Published: 2021-12-10

QID 730296: Atlassian Jira Server and Data Center Denial of Service (DoS) Vulnerability (JRASERVER-72914)

Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.

CVE-2021-42340:Jira is affected by Tomcat Denial of service via an OutOfMemoryError - a memory leak that, over time, could lead to a denial of service.

Affected version:
Atlassian Jira Server and Data Center version from 8.15.x to 8.20.x

QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.

A memory leak that, over time, could lead to a Denial of Service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to JRASERVER-72914 for updates pertaining to this vulnerability.
    Workaround:
    You can update the version of Tomcat Server to fix the vulnerability by following the steps provided Upgrade Tomcat
    Vendor References

    CVEs related to QID 730296

    Software Advisories
    Advisory ID Software Component Link
    JRASERVER-72914 URL Logo jira.atlassian.com/browse/JRASERVER-72914