Uploaded image for project: 'Jira Cloud'
  1. Jira Cloud
  2. JRACLOUD-66120

Bruteforce Attack via Applinks Servlet

    XMLWordPrintable

Details

    Description

      An attacker is able to perform bruteforce attacks via the applinks servlet. There is no captcha protection, nor do accounts get locked out after excessive attempts.

      The attacker can input a username, and perform bruteforce attacks on the login form. The core issue is that there is no login attempt limitation for an attacker.

      The bruteforce attack can be executed through the form on:
      https://example.com/plugins/servlet/applinks/login on a standard JIRA installation.

      This vulnerability was reported by Nir Goldshlager ngoldshlager@salesforce.com.

      Attachments

        1. newapplauth1.png
          48 kB
        2. newapplauth2.png
          37 kB

        Issue Links

          Activity

            People

              ohernandez@atlassian.com Oswaldo Hernandez (Inactive)
              73e00aef4e3f Nir Goldshlager
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: