Improper authorization in Atlassian Jira



Published: 2021-11-04
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2021-41312
CWE-ID CWE-285
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Jira Software
Client/Desktop applications / Other client software

Vendor Atlassian

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Improper Authorization

EUVDB-ID: #VU57963

Risk: Low

CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-41312

CWE-ID: CWE-285 - Improper Authorization

Exploit availability: No

Description

The vulnerability allows a remote user to bypass authorization process.

The vulnerability exists due to an error in when processing requests in the /secure/ViewCollectors endpoint. A remote user with revoked access from the Jira Service Management can enable and disable Issue Collectors on Jira Service Management projects.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Jira Software: 8.19.0

External links

http://jira.atlassian.com/browse/JRASERVER-72801


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###