-
Public Security Vulnerability
-
Resolution: Fixed
-
Low
-
4.22.5
-
2.6
-
Low
The mail handler in Jira Service Management (JSM) Server and Data Center 4.22.5 incorrectly maps new incoming emails to the wrong JSM project, instead of the project linked to the mailbox the mails were sent to. If JSM is configured to process emails and create tickets in a restricted-access project, it may incorrectly create tickets in a widely accessible project, resulting in information disclosure.
Affected version
- 4.22.5
Fixed versions
- 4.22.x >= 4.22.6
- details
-
JSDSERVER-11884 The JSM Mail Handler functionality creates tickets from incoming emails in wrong projects
-
- Closed
-
[JSDSERVER-11888] The Mail Handler creates tickets from incoming emails in the wrong projects
Security | Original: Atlassian Staff [ 10750 ] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Draft [ 12872 ] | New: Published [ 12873 ] |
Labels | Original: advisory advisory-to-release dont-import security 🔢✅ | New: advisory advisory-released dont-import security 🔢✅ |
Description |
Original:
This vulnerability affects certain versions of Atlassian Jira Service Management Server. Please describe the impact of the vulnerability here. No known vulnerability could be read off of the parent. |
New:
The mail handler in Jira Service Management (JSM) Server and Data Center 4.22.5 incorrectly maps new incoming emails to the wrong JSM project, instead of the project linked to the mailbox the mails were sent to. If JSM is configured to process emails and create tickets in a restricted-access project, it may incorrectly create tickets in a widely accessible project, resulting in information disclosure.
h3. Affected version * 4.22.5 h3. Fixed versions * 4.22.x >= 4.22.6 |
Summary | Original: An Atlassian product has a security vulnerability. | New: The Mail Handler creates tickets from incoming emails in the wrong projects |
Component/s | New: Email - Incoming [ 32490 ] |
Labels | Original: advisory advisory-to-release dont-import security | New: advisory advisory-to-release dont-import security 🔢✅ |
Link |
New:
This issue details |
Labels | New: advisory advisory-to-release dont-import security |
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 2.6 => Low severity
Exploitability Metrics
Scope Metric
Impact Metrics
https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N