Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-72433

Reverse tabnapping via Project Shortcuts feature - CVE-2021-39112

    • 3
    • Low
    • CVE-2021-39112

      Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature.

      The affected versions are before version 8.5.15, from version 8.6.0 before 8.13.7, from version 8.14.0 before 8.17.1, and from version 8.18.0 before 8.18.1.

       

      Affected versions:

      • version < 8.5.15
      • 8.6.0 ≤ version < 8.13.7
      • 8.14.0 ≤ version < 8.17.1
      • 8.18.0 ≤ version < 8.18.1

      Fixed versions:

      • 8.5.15
      • 8.13.7
      • 8.17.1
      • 8.18.1  

          Form Name

            [JRASERVER-72433] Reverse tabnapping via Project Shortcuts feature - CVE-2021-39112

            AB added a comment - - edited

            This is an independent assessment and you should evaluate its applicability to your own IT environment.

            CVSS v3 score: 2.4 => Low severity

            Exploitability Metrics

            Attack Vector Network
            Attack Complexity Low
            Privileges Required High
            User Interaction Required

            Scope Metric

            Scope Unchanged

            Impact Metrics

            Confidentiality None
            Integrity Low
            Availability None

            https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

            AB added a comment - - edited This is an independent assessment and you should evaluate its applicability to your own IT environment. CVSS v3 score: 2.4 => Low severity Exploitability Metrics Attack Vector Network Attack Complexity Low Privileges Required High User Interaction Required Scope Metric Scope Unchanged Impact Metrics Confidentiality None Integrity Low Availability None https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: