Bruteforce Attack via Applinks Servlet

XMLWordPrintable

    • 6

      An attacker is able to perform bruteforce attacks via the applinks servlet. There is no captcha protection, nor do accounts get locked out after excessive attempts.

      The attacker can input a username, and perform bruteforce attacks on the login form. The core issue is that there is no login attempt limitation for an attacker.

      The bruteforce attack can be executed through the form on:
      https://example.com/plugins/servlet/applinks/login on a standard JIRA installation.

      This vulnerability was reported by Nir Goldshlager ngoldshlager@salesforce.com.

        1. newapplauth1.png
          48 kB
          Grzegorz Tanczyk
        2. newapplauth2.png
          37 kB
          Grzegorz Tanczyk

            Assignee:
            Oswaldo Hernandez (Inactive)
            Reporter:
            Nir Goldshlager
            Votes:
            0 Vote for this issue
            Watchers:
            8 Start watching this issue

              Created:
              Updated:
              Resolved: