Uploaded image for project: 'Jira Software Data Center'
  1. Jira Software Data Center
  2. JSWSERVER-20111

Denial of service in issue searching through Epic Name ordering - CVE-2019-11583

      The issue searching component in Jira before version 8.1.0 allows remote attackers to
      deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name".

            [JSWSERVER-20111] Denial of service in issue searching through Epic Name ordering - CVE-2019-11583

            set-jac-bot made changes -

            sbrown added a comment -

            @SecurityB, looking for clarity on the vulnerable versions.

            Is it just 7.13.4 or 7.13.4 or greater?

            sbrown added a comment - @SecurityB, looking for clarity on the vulnerable versions. Is it just 7.13.4 or 7.13.4 or greater?

            Vas91 added a comment - - edited

            @SecurityB

            Please let me know about the status of versions 7.13.x  greater than  7.13.4

             

            Thanks!

            Vas91 added a comment - - edited @SecurityB Please let me know about the status of versions 7.13.x  greater than  7.13.4   Thanks!
            Said made changes -
            Labels Original: CVE-2019-11583 advisory advisory-released cvss-medium denial-of-service pse-request security New: CVE-2019-11583 advisory advisory-released application-dos cvss-medium denial-of-service pse-request security

            Is there any workaround for this bug? or do we need to upgrade immediately? We are in version 7.13.2

            Prashant Karakanagoudar added a comment - Is there any workaround for this bug? or do we need to upgrade immediately? We are in version 7.13.2

            Is it fixed on version 7.13.4 and above or just the version 7.13.14? We are at 7.13.8 so do we need to upgrade to apply the fix?

            Manoj Chhetry added a comment - Is it fixed on version 7.13.4 and above or just the version 7.13.14? We are at 7.13.8 so do we need to upgrade to apply the fix?
            Robbie (Inactive) made changes -
            Fix Version/s New: 7.13.4 [ 86493 ]
            Clement made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 442441 ]
            David Black made changes -
            Description Original: obfuscated description New: obfuscated description
            David Black made changes -
            Description Original: obfuscated description New: obfuscated description

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              13 Start watching this issue

                Created:
                Updated:
                Resolved: