Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-72803

Access-revoked user can view audit logs of Jira Projects - CVE-2021-41309

    • 4.3
    • Medium
    • CVE-2021-41309

      Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs of another user's Jira Service Management project via a Broken Authentication vulnerability in the /plugins/servlet/audit/resource endpoint.

      The affected versions of Jira Server and Data Center are before version 8.19.1.

      *Affected versions:*

      • version < 8.19.1

      *Fixed versions:*

      • 8.19.1

            [JRASERVER-72803] Access-revoked user can view audit logs of Jira Projects - CVE-2021-41309

            André Rossky added a comment - - edited

            Hello team,

            same question as for https://jira.atlassian.com/browse/JRASERVER-72802,

            Will the fix be ported to the 8.13 LTS? Several 8.13 patch versions were released since the fix, why wasn't the fix backported? Affected versions list 8.13.10 while 8.13.15 is the last released patch version of the 8.13 line, this is confusing.
            

            Thanks,
            André

            André Rossky added a comment - - edited Hello team, same question as for https://jira.atlassian.com/browse/JRASERVER-72802 , Will the fix be ported to the 8.13 LTS? Several 8.13 patch versions were released since the fix, why wasn't the fix backported? Affected versions list 8.13.10 while 8.13.15 is the last released patch version of the 8.13 line, this is confusing. Thanks, André

            AB added a comment - - edited

            This is an independent assessment and you should evaluate its applicability to your own IT environment.

            CVSS v3 score: 4.3 => Medium severity

            Exploitability Metrics

            Attack Vector Network
            Attack Complexity Low
            Privileges Required Low
            User Interaction None

            Scope Metric

            Scope Unchanged

            Impact Metrics

            Confidentiality Low
            Integrity None
            Availability None

            https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

            AB added a comment - - edited This is an independent assessment and you should evaluate its applicability to your own IT environment. CVSS v3 score: 4.3 => Medium severity Exploitability Metrics Attack Vector Network Attack Complexity Low Privileges Required Low User Interaction None Scope Metric Scope Unchanged Impact Metrics Confidentiality Low Integrity None Availability None https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: