Vulnerabilities > CVE-2017-18101 - Missing Authorization vulnerability in Atlassian Jira
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7.6.5, from version 7.7.0 before version 7.7.3, from version 7.8.0 before version 7.8.3 and before version 7.9.0 allow remote attackers to run import operations and to determine if an internal service exists through missing permission checks.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family | CGI abuses |
NASL id | JIRA_7_6_5.NASL |
description | According to its self-reported version number, the instance of Atlassian JIRA hosted on the remote web server is potentially affected by an authentication bypass on certain administrative resources, which could allow an attacker to run import operations or reveal sensitive information. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 122598 |
published | 2019-03-05 |
reporter | This script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/122598 |
title | Atlassian JIRA < 7.6.5 / 7.7.x < 7.7.3 / 7.8.x < 7.8.3 Limited Authentication Bypass |
code |
|