PT-2024-4436 · Atlassian · Jira+1
Published
2024-05-14
·
Updated
2024-06-20
·
CVE-2024-21685
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jira Core Data Center versions 9.4.0 through 9.15.0
Jira Core Data Center version 9.12.0
Description
The issue is related to insufficient protection of internal data in Atlassian Jira Data Center and Jira Server, allowing a remote attacker to gain unauthorized access to protected information. This Information Disclosure issue allows an unauthenticated attacker to view sensitive information, which has a high impact on confidentiality. The vulnerability was found internally and requires user interaction.
Recommendations
For Jira Core Data Center 9.4: Upgrade to a release greater than or equal to 9.4.21
For Jira Core Data Center 9.12: Upgrade to a release greater than or equal to 9.12.8
For Jira Core Data Center 9.16: Upgrade to a release greater than or equal to 9.16.0
As a temporary workaround, consider restricting access to sensitive information until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jira
Jira Core