PT-2021-16941 · Atlassian · Connect Spring Boot
Published
2021-04-16
·
Updated
2025-02-12
·
CVE-2021-26074
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Atlassian Connect Spring Boot versions 1.1.0 through 2.1.2
Description
The issue concerns broken authentication in Atlassian Connect Spring Boot, a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the app occurs via a server-to-server JWT or a context JWT. However, versions of Atlassian Connect Spring Boot from 1.1.0 before 2.1.3 incorrectly accept context JWTs in lifecycle endpoints, such as installation, where only server-to-server JWTs should be accepted. This allows an attacker to send authenticated re-installation events to an app.
Recommendations
For Atlassian Connect Spring Boot versions 1.1.0 through 2.1.2, update to version 2.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to lifecycle endpoints, such as installation, to minimize the risk of exploitation.
Fix
Improper Authentication
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Connect Spring Boot