PT-2024-2154 · Atlassian · Jira Service Management Server+1
Published
2024-02-20
·
Updated
2024-08-28
·
CVE-2024-21682
CVSS v2.0
8.3
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Assets Discovery versions 1.0 through 6.2.0
Description
This issue allows an authenticated attacker to modify system calls, potentially impacting confidentiality, integrity, and availability. It requires no user interaction. Assets Discovery is a network scanning tool used with Jira Service Management Cloud, Data Center, or Server to detect and extract information about hardware and software on the local network.
Recommendations
For versions 1.0 through 6.2.0, upgrade to the latest version of Assets Discovery. If upgrading is not possible, upgrade your instance to one of the specified supported fixed versions. As a temporary workaround, consider restricting access to the vulnerable components of Assets Discovery until a patch is available.
Fix
Improper Authentication
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jira Service Management Cloud
Jira Service Management Server