Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-73811

IDOR (Insecure direct object references) in Jira 8.13.10

      We have found during testing that by sending a fake header with a domain name (supplying as a suffix (i.e. attack.eu)) into the Host header field, the web server processes the input to send the request to an attacker-controlled host that resides at the supplied domain, and not to an internal virtual host that resides on the web server.

      Affected versions:

      • 8.13.10

      Earlier fixed versions:

      • 7.13.16
      • 8.5.7
      • 8.9.2
      • 8.10.1
      • 8.11.0

            [JRASERVER-73811] IDOR (Insecure direct object references) in Jira 8.13.10

            Security Metrics Bot made changes -
            Labels Original: 2af advisory advisory-released bugbounty cve-2020-14174 cvss-low idor monsters security security-imported New: 2af advisory advisory-released bugbounty cve-2020-14174 cvss-low idor monsters resolved-in-vf security security-imported
            Karol Skwierawski made changes -
            Fix Version/s New: 8.15.0 [ 92948 ]
            Karol Skwierawski made changes -
            Fix Version/s New: 8.13.2 [ 92949 ]
            Karol Skwierawski made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Short Term Backlog [ 12074 ] New: Closed [ 6 ]
            Marcin Oles made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 963362 ]
            SET Analytics Bot made changes -
            UIS Original: 6 New: 3
            SET Analytics Bot made changes -
            UIS Original: 7 New: 6
            SET Analytics Bot made changes -
            UIS Original: 3 New: 7
            SET Analytics Bot made changes -
            Support reference count Original: 2 New: 3
            John Vecchio made changes -
            Affects Version/s New: 9.4.0 [ 102402 ]
            Affects Version/s New: 9.4.9 [ 105514 ]

              4e432536cf93 Karol Skwierawski
              f956e0e022e9 skavatekar
              Affected customers:
              2 This affects my team
              Watchers:
              14 Start watching this issue

                Created:
                Updated:
                Resolved: