PT-2021-16940 · Atlassian · Connect Express

Published

2021-04-16

·

Updated

2025-02-12

·

CVE-2021-26073

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Atlassian Connect Express versions 3.0.2 through 6.6.0
Description The issue concerns broken authentication in Atlassian Connect Express, a Node.js package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Express app occurs with a server-to-server JWT or a context JWT. However, Atlassian Connect Express versions from 3.0.2 before 6.6.0 incorrectly accept context JWTs in lifecycle endpoints, such as installation, where only server-to-server JWTs should be accepted. This allows an attacker to send authenticated re-installation events to an app.
Recommendations For versions 3.0.2 through 6.6.0, update to version 6.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to lifecycle endpoints, such as installation, to minimize the risk of exploitation. Avoid using context JWTs in these endpoints until the issue is resolved.

Fix

Improper Authentication

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-26073
GHSA-4V96-M8XV-X83V

Affected Products

Connect Express