-
Bug
-
Resolution: Fixed
-
Low
-
7.6.15, 8.5.4, 7.13.13, 8.8.0, 9.4.14
-
7.06
-
26
-
Severity 3 - Minor
-
7
-
Issue Summary
"About Jira" page can be accessed anonymously. This can expose the Jira application versions. Some customers might want to prevent this information from being available as it could be used to target other vulnerabilities specific to the version.
Steps to Reproduce
Access <JIRA BASE URL>/secure/AboutPage.jspa anonymously
Expected Results
The user gets redirected to log in
Actual Results
Notes
This happens even if the public access is blocked using a flag in the dark features
Workaround
Create a block the URL from being accessed from the proxy side. Another option is doing it from Apache Tomcat: How to block access to a specific URL at Tomcat
- is related to
-
JRASERVER-71317 Browsing serverInfo anonymously gives version number information
- Gathering Impact
-
JRASERVER-62282 Ability to disable/hide the REST endpoint for serverInfo
- Gathering Interest
- relates to
-
VULN-164510 Loading...
-
RM-22091 Loading...