PT-2021-4639 · Atlassian+8 · Jira+11

Nicholas Boucher

+1

·

Published

2021-11-01

·

Updated

2024-08-04

·

CVE-2021-42574

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Unicode Specification versions prior to 14.0 Jira Service Management (affected versions not specified) Jira Software (affected versions not specified) Jira Work Management (affected versions not specified)
Description The issue is related to the Bidirectional Algorithm in the Unicode Specification, which can be exploited to introduce targeted vulnerabilities invisibly to human reviewers. This is achieved by crafting source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. The Unicode Consortium has documented this class of vulnerability and provides guidance on mitigations. The vulnerability can affect applications that implement support for the Unicode Standard and the Unicode Bidirectional Algorithm. It is also known as the Trojan Source attack, which allows an adversary to encode source code for compilers accepting Unicode, introducing vulnerabilities that are not visible to human reviewers.
Recommendations For Unicode Specification versions prior to 14.0: Consider implementing the guidance on mitigations provided by the Unicode Consortium in Unicode Technical Standard #39, Unicode Security Mechanisms, and in Unicode Standard Annex #31, Unicode Identifier and Pattern Syntax. For Jira Service Management, Jira Software, and Jira Work Management: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

RCE

Weakness Enumeration

Related Identifiers

ALSA-2021:4585
ALSA-2021:4586
ALSA-2021:4587
ALSA-2021:4590
ALSA-2021:4591
ALSA-2021:4592
ALSA-2021:4593
ALSA-2021:4594
ALSA-2021:4595
ALSA-2021:4649
ALSA-2021:4743
ALSA-2021_4585
ALSA-2021_4586
ALSA-2021_4587
ALSA-2021_4590
ALSA-2021_4591
ALSA-2021_4592
ALSA-2021_4593
ALSA-2021_4594
ALSA-2021_4595
ALSA-2021_4649
ALSA-2021_4743
ALT-PU-2021-3225
ALT-PU-2021-3390
ALT-PU-2022-1106
ALT-PU-2022-2927
ALT-PU-2023-1135
ALT-PU-2023-4337
BDU:2021-05328
CESA-2021_4033
CESA-2021_4585
CESA-2021_4586
CESA-2021_4587
CESA-2021_4590
CESA-2021_4591
CESA-2021_4592
CESA-2021_4593
CESA-2021_4594
CESA-2021_4595
CESA-2021_4649
CESA-2021_4743
CESA-2022_1894
CVE-2021-42574
ELSA-2021-4033
ELSA-2021-4585
ELSA-2021-4586
ELSA-2021-4587
ELSA-2021-4590
ELSA-2021-4591
ELSA-2021-4592
ELSA-2021-4593
ELSA-2021-4594
ELSA-2021-4595
ELSA-2021-4649
ELSA-2021-4743
MGASA-2021-0517
OESA-2022-1501
OPENSUSE-SU-2024:11650-1
RHSA-2021:4033
RHSA-2021:4034
RHSA-2021:4035
RHSA-2021:4036
RHSA-2021:4037
RHSA-2021:4038
RHSA-2021:4039
RHSA-2021:4585
RHSA-2021:4586
RHSA-2021:4587
RHSA-2021:4588
RHSA-2021:4589
RHSA-2021:4590
RHSA-2021:4591
RHSA-2021:4592
RHSA-2021:4593
RHSA-2021:4594
RHSA-2021:4595
RHSA-2021:4596
RHSA-2021:4598
RHSA-2021:4599
RHSA-2021:4600
RHSA-2021:4601
RHSA-2021:4602
RHSA-2021:4649
RHSA-2021:4669
RHSA-2021:4694
RHSA-2021:4723
RHSA-2021:4724
RHSA-2021:4729
RHSA-2021:4730
RHSA-2021:4743
RHSA-2021_4033
RHSA-2021_4585
RHSA-2021_4586
RHSA-2021_4587
RHSA-2021_4590
RHSA-2021_4591
RHSA-2021_4592
RHSA-2021_4593
RHSA-2021_4594
RHSA-2021_4595
RHSA-2021_4649
RHSA-2021_4743
RHSA-2022_1894
RLSA-2021:4585
RLSA-2021:4586
RLSA-2021:4587
RLSA-2021:4590
RLSA-2021:4591
RLSA-2021:4592
RLSA-2021:4593
RLSA-2021:4594
RLSA-2021:4595
RLSA-2021:4649
RLSA-2021:4743
RLSA-2021_4585
RLSA-2021_4586
RLSA-2021_4587
RLSA-2021_4590
RLSA-2021_4591
RLSA-2021_4592
RLSA-2021_4593
RLSA-2021_4594
RLSA-2021_4595
RLSA-2021_4649
RLSA-2021_4743

Affected Products

Alt Linux
Almalinux
Astra Linux
Bamboo
Centos
Debian
Jira
Jira Service Management Server
Jira Work Management
Red Hat
Rocky Linux
Unicode Specification