Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-72029

Gadget resource makeRequest defeats behind-the-firewall protection of app-linked resources - CVE-2021-26070

    • 7.5
    • High
    • CVE-2021-26070

      Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource.

      The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.

       

      Affected versions:

      • version < 8.13.3
      • 8.14.0 ≤ version < 8.14.1

      Fixed versions:

      • 8.13.3
      • 8.14.1
      • 8.15.0  

       

            [JRASERVER-72029] Gadget resource makeRequest defeats behind-the-firewall protection of app-linked resources - CVE-2021-26070

            Is it planned to include the fix in any 8.5 versions?

            Patrice Lassalle added a comment - Is it planned to include the fix in any 8.5 versions?

            Hi a197d08fc5ad,
            We have updated the CVE id reference for this issue.

            David Black added a comment - Hi a197d08fc5ad , We have updated the CVE id reference for this issue.

            NVD suggests this vulnerability to be associated with CVE ID: CVE-2021-26070

            Anything on the same??

            Jay Kapadiya added a comment - NVD suggests this vulnerability to be associated with CVE ID: CVE-2021-26070 Anything on the same??

            AB added a comment -

            This is an independent assessment and you should evaluate its applicability to your own IT environment.

            CVSS v3 score: 7.2 => High severity

            Exploitability Metrics

            Attack Vector Network
            Attack Complexity Low
            Privileges Required None
            User Interaction None

            Scope Metric

            Scope Changed

            Impact Metrics

            Confidentiality Low
            Integrity Low
            Availability None

             

            AB added a comment - This is an independent assessment and you should evaluate its applicability to your own IT environment. CVSS v3 score: 7.2 => High severity Exploitability Metrics Attack Vector Network Attack Complexity Low Privileges Required None User Interaction None Scope Metric Scope Changed Impact Metrics Confidentiality Low Integrity Low Availability None  

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: