QID 730973
Date Published: 2023-11-16
QID 730973: Atlassian Jira Server File Upload Vulnerability
Affected versions of Atlassian Jira Server/DC allows an unauthenticated attacker to upload arbitrary files to Jira via file upload functionality in the fileupload url. However An attacker cannot control the filename or its location, which prevents the possibility of RCE.
Affected Versions
9.4.0, 8.13.27, 8.20.14, 9.4.3, 8.20.18
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Successful exploitation of this vulnerability could lead to a security breach or could affect confidentiality, integrity, and availability.
Solution
Customers are advised to refer to JRASERVER-75331 for updates pertaining to this vulnerability.
Vendor References
- JRASERVER-75331 -
jira.atlassian.com/browse/JRASERVER-75331
CVEs related to QID 730973
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-75331 |
|