PT-2021-16941 · Atlassian · Connect Spring Boot

Published

2021-04-16

·

Updated

2025-02-12

·

CVE-2021-26074

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Atlassian Connect Spring Boot versions 1.1.0 through 2.1.2
Description The issue concerns broken authentication in Atlassian Connect Spring Boot, a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the app occurs via a server-to-server JWT or a context JWT. However, versions of Atlassian Connect Spring Boot from 1.1.0 before 2.1.3 incorrectly accept context JWTs in lifecycle endpoints, such as installation, where only server-to-server JWTs should be accepted. This allows an attacker to send authenticated re-installation events to an app.
Recommendations For Atlassian Connect Spring Boot versions 1.1.0 through 2.1.2, update to version 2.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to lifecycle endpoints, such as installation, to minimize the risk of exploitation.

Fix

Improper Authentication

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-26074
GHSA-CPCR-74Q9-74GP

Affected Products

Connect Spring Boot