Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-72802

Access-revoked user can add new users and groups to a Jira project - CVE-2021-41311

    • 7.5
    • High
    • CVE-2021-41311

      Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint.

      The affected versions are before version 8.19.1.

      Affected versions:

      • version < 8.19.1

      Fixed versions:

      • 8.19.1

            [JRASERVER-72802] Access-revoked user can add new users and groups to a Jira project - CVE-2021-41311

            Danny Prill added a comment - - edited

            f

            Danny Prill added a comment - - edited f

            Dear Atlassian-Team, will be the LTS Version of Jira patched? Or is Jira 8.13.5 not affected?

            Tomasz Baszczynski added a comment - Dear Atlassian-Team, will be the LTS Version of Jira patched? Or is Jira 8.13.5 not affected?

            Will the fix be ported to the 8.13 LTS? Several 8.13 patch versions were released since the fix, why wasn't the fix backported? Affected versions list 8.13.10 while 8.13.15 is the last released patch version of the 8.13 line, this is confusing.

            We would like to evault the applicability to our own IT environment, but how can the vulnerability be reproduced? It is unclear what "administrator account that has had its access revoked" means exactly and what is "Broken Authentication vulnerability" and how it can be used to modify project's user and roles?

             

             

            Performation Healthcare Intelligence BV added a comment - Will the fix be ported to the 8.13 LTS? Several 8.13 patch versions were released since the fix, why wasn't the fix backported? Affected versions list 8.13.10 while 8.13.15 is the last released patch version of the 8.13 line, this is confusing. We would like to evault the applicability to our own IT environment, but how can the vulnerability be reproduced? It is unclear what "administrator account that has had its access revoked" means exactly and what is "Broken Authentication vulnerability" and how it can be used to modify project's user and roles?    

            AB added a comment - - edited

            This is an independent assessment and you should evaluate its applicability to your own IT environment.

            CVSS v3 score: 7.5 => High severity

            Exploitability Metrics

            Attack Vector Network
            Attack Complexity Low
            Privileges Required None
            User Interaction None

            Scope Metric

            Scope Unchanged

            Impact Metrics

            Confidentiality High
            Integrity None
            Availability None

            https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

            AB added a comment - - edited This is an independent assessment and you should evaluate its applicability to your own IT environment. CVSS v3 score: 7.5 => High severity Exploitability Metrics Attack Vector Network Attack Complexity Low Privileges Required None User Interaction None Scope Metric Scope Unchanged Impact Metrics Confidentiality High Integrity None Availability None https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: