PT-2021-16940 · Atlassian · Connect Express
Published
2021-04-16
·
Updated
2025-02-12
·
CVE-2021-26073
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Atlassian Connect Express versions 3.0.2 through 6.6.0
Description
The issue concerns broken authentication in Atlassian Connect Express, a Node.js package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Express app occurs with a server-to-server JWT or a context JWT. However, Atlassian Connect Express versions from 3.0.2 before 6.6.0 incorrectly accept context JWTs in lifecycle endpoints, such as installation, where only server-to-server JWTs should be accepted. This allows an attacker to send authenticated re-installation events to an app.
Recommendations
For versions 3.0.2 through 6.6.0, update to version 6.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to lifecycle endpoints, such as installation, to minimize the risk of exploitation. Avoid using context JWTs in these endpoints until the issue is resolved.
Fix
Improper Authentication
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Connect Express