Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-75331

Malicious file upload in Jira Server via anonymous sources

    • 5.3
    • Medium

      Affected versions of Atlassian Jira Server/DC allows an unauthenticated attacker to upload arbitrary files to Jira via file upload functionality in the fileupload url. However An attacker cannot control the filename or its location, which prevents the possibility of RCE.

      Files with name start with multPartReq with .tmp filename may be seen in "<JIRA_INSTALL>/work" path location due to this bug.

       
      Affected versions:

      • version < 9.4.0
      • 9.4.0 < version < 9.4.3
      • version <= 8.20.18
      • version <= 8.13.27

      Fixed versions: 

      • 9.4.4
      • 8.20.20
      • 9.5.4

            [JRASERVER-75331] Malicious file upload in Jira Server via anonymous sources

            Jonathan Soo made changes -
            Remote Link Original: This issue links to "VULN-833557 (Atlassian Security Jira)" [ 749447 ] New: This issue links to "VULN-833557 (ASEC/J)" [ 749447 ]

            Yes, this has cleared my confusion. Thank you.

            Amr Hamza (Legacy) added a comment - Yes, this has cleared my confusion. Thank you.

            146dab3de87d Our 9.4 releases are LTS release. Reading this means, 9.4.4 is when this fixed and all releases after but within 9.4.x has the fix. At this point of writing, 9.4.4 until 9.4.7 has the fix. Hope this helps.

            Zul NS [Atlassian] added a comment - 146dab3de87d Our 9.4 releases are LTS release. Reading this means, 9.4.4 is when this fixed and all releases after but within 9.4.x has the fix. At this point of writing, 9.4.4 until 9.4.7 has the fix. Hope this helps.

            Is 9.4.4 the only fix version or is it 9.4.4 and higher? Thanks.

            Amr Hamza (Legacy) added a comment - Is 9.4.4 the only fix version or is it 9.4.4 and higher? Thanks.
            Manisha Sangwan made changes -
            Security Original: Reporter and Atlassian Staff [ 10751 ]
            Manisha Sangwan made changes -
            Labels Original: dont-import security 🔢✅ New: advisory-released dont-import security 🔢✅
            Manisha Sangwan made changes -
            Labels Original: advisory advisory-released dont-import security 🔢✅ New: dont-import security 🔢✅
            Manisha Sangwan made changes -
            Resolution New: Fixed [ 1 ]
            Security Original: Atlassian Staff [ 10750 ] New: Reporter and Atlassian Staff [ 10751 ]
            Status Original: Draft [ 12872 ] New: Published [ 12873 ]
            Zul NS [Atlassian] made changes -
            Description Original: Affected versions of Atlassian Jira Server/DC allows an unauthenticated attacker to upload arbitrary files to Jira via file upload functionality in the fileupload url. However An attacker cannot control the filename or its location, which prevents the possibility of RCE.

             
            Affected versions:
             * version < 9.4.0
             * 9.4.0 < version < 9.4.3
             * version <= 8.20.18
             * version <= 8.13.27

            Fixed versions: 
             * 9.4.4
             * 8.20.20
             * 9.5.4
            New: Affected versions of Atlassian Jira Server/DC allows an unauthenticated attacker to upload arbitrary files to Jira via file upload functionality in the fileupload url. However An attacker cannot control the filename or its location, which prevents the possibility of RCE.

            Files with name start with {{multPartReq}} with {{.tmp}} filename may be seen in "<JIRA_INSTALL>/work" path location due to this bug.

             
            Affected versions:
             * version < 9.4.0
             * 9.4.0 < version < 9.4.3
             * version <= 8.20.18
             * version <= 8.13.27

            Fixed versions: 
             * 9.4.4
             * 8.20.20
             * 9.5.4
            Manisha Sangwan made changes -
            Remote Link New: This issue links to "VULN-833557 (Atlassian Security Jira)" [ 749447 ]

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: