Affected versions of Atlassian Jira Server and Data Centre allowed an unauthenticated remote attacker to fetch Issue,Project and Sprint information via Information Disclosure Vulnerability via "/secure/QueryComponentRendererValue!Default.jspa" endpoint.

      Affected versions:

      • version < 9.5.1

      Fixed versions:

      • 8.20.21 and newer
      • 9.4.4 and newer
      • 9.5.1 and newer
      • 9.6.0 and newer

            [JRASERVER-74771] Information Disclosure via QueryCompenentRenderer API

            Bugfix Automation Bot made changes -
            Introduced in Version New: 8.2
            Soner Sezgin made changes -
            Symptom Severity New: Severity 2 - Major [ 15831 ]
            Workflow Original: JAC Public Security Vulnerability Workflow v2 [ 4341798 ] New: JAC Bug Workflow v3 [ 4510126 ]
            Issue Type Original: Public Security Vulnerability [ 10700 ] New: Bug [ 1 ]
            Status Original: Published [ 12873 ] New: Closed [ 6 ]

            David Yu added a comment -

            Having been previously bitten by JRASERVER-71536 (/secure/QueryComponent.jspa), I setup a forced authentication rule with Resolution SSO for SAML, and forced auth on all endpoints /secure/*. Looks like that rule came in handy here as I missed the annoucement for this vuln. Highly recommend especially if you are already using it.

            David Yu added a comment - Having been previously bitten by JRASERVER-71536 (/secure/QueryComponent.jspa), I setup a forced authentication rule with Resolution SSO for SAML, and forced auth on all endpoints /secure/* . Looks like that rule came in handy here as I missed the annoucement for this vuln. Highly recommend especially if you are already using it.

            Ranjith Koolath added a comment - - edited

            You may consider employing a workaround by limiting the endpoint for users without authentication. The necessary steps can be found in this knowledge base article: : https://confluence.atlassian.com/jirakb/restrict-unauthenticated-access-for-some-jira-endpoints-1206796039.html

            Ranjith Koolath added a comment - - edited You may consider employing a workaround by limiting the endpoint for users without authentication. The necessary steps can be found in this knowledge base article: : https://confluence.atlassian.com/jirakb/restrict-unauthenticated-access-for-some-jira-endpoints-1206796039.html
            Kaili Gu made changes -
            Link New: This issue has a derivative of JRASERVER-76261 [ JRASERVER-76261 ]
            Cathy S made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 765126 ]

            Sue Webber added a comment -

            If unable to update our version right now, is there a workaround that can be applied as is normally the case ?

            Sue Webber added a comment - If unable to update our version right now, is there a workaround that can be applied as is normally the case ?

            Thanks Bruno. 

            Much appreciated.

            Peter Mavridis added a comment - Thanks Bruno.  Much appreciated.

            Bruno added a comment -

            Hey 40a60042dfe3 , thank you for asking!

            Yes, once the fix is included in 9.4.4, all 9.4.x newer versions (9.4.5, 9.4.6, ...) will have the fix included. 
            The same happens for 9.5.x where the issue is fixed on 9.5.1. All newer versions (9.5.2, 9.5.3, ...) will have the fix included. 

            I have edited the Description to be a bit more clear. 

            I hope it helps.

            Bruno added a comment - Hey 40a60042dfe3 , thank you for asking! Yes, once the fix is included in 9.4.4, all 9.4.x newer versions (9.4.5, 9.4.6, ...) will have the fix included.  The same happens for 9.5.x where the issue is fixed on 9.5.1. All newer versions (9.5.2, 9.5.3, ...) will have the fix included.  I have edited the Description to be a bit more clear.  I hope it helps.
            Bruno made changes -
            Description Original: Affected versions of Atlassian Jira Server and Data Centre allowed an unauthenticated remote attacker to fetch Issue,Project and Sprint information via Information Disclosure Vulnerability via "/secure/QueryComponentRendererValue!Default.jspa" endpoint.

            *Affected versions:*
             * version < 9.5.1

            *Fixed versions:*
             * 9.5.1
             * 9.6.0
            New: Affected versions of Atlassian Jira Server and Data Centre allowed an unauthenticated remote attacker to fetch Issue,Project and Sprint information via Information Disclosure Vulnerability via "/secure/QueryComponentRendererValue!Default.jspa" endpoint.

            *Affected versions:*
             * version < 9.5.1

            *Fixed versions:*
             * 8.20.21 and newer
             * 9.4.4 and newer
             * 9.5.1 and newer
             * 9.6.0 and newer

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              43 Start watching this issue

                Created:
                Updated:
                Resolved: