[{"advisory":{"name":"Jira Service Desk Security Advisory 2019-09-18","url":"https://confluence.atlassian.com/adminjiraserver/jira-service-desk-security-advisory-2019-09-18-1047539909.html"},"cveId":"CVE-2019-14994","description":"The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, from version 4.3.0 before version 4.3.4, and version 4.4.0 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via a path traversal vulnerability. Note that when the 'Anyone can email the service desk or raise a request in the portal' setting is enabled, an attacker can grant themselves portal access, allowing them to exploit the vulnerability.","baseScore":7.5,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"3.9.16"},{"versionStartIncluding":"3.10.0","versionEndExcluding":"3.16.8"},{"versionStartIncluding":"3.10.0","versionEndExcluding":"3.16.8"},{"versionStartIncluding":"4.0.0","versionEndExcluding":"4.1.3"},{"versionStartIncluding":"4.2.0","versionEndExcluding":"4.2.5"},{"versionStartIncluding":"4.3.0","versionEndExcluding":"4.3.4"},{"versionStartIncluding":"4.4.0","versionEndExcluding":"4.4.1"}]},{"advisory":{"name":"Jira Service Desk Security Advisory 2019-11-06","url":"https://confluence.atlassian.com/adminjiraserver/jira-service-desk-security-advisory-2019-11-06-1047539905.html"},"cveId":"CVE-2019-15003","description":"The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, and from 4.5.0 before 4.5.1 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via authorization bypass. Note that when the 'Anyone can email the service desk or raise a request in the portal' setting is enabled, an attacker can grant themselves portal access, allowing them to exploit the vulnerability.","baseScore":5.3,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"3.9.17"},{"versionStartIncluding":null,"versionEndExcluding":"3.9.17"},{"versionStartIncluding":"3.10.0","versionEndExcluding":"3.16.10"},{"versionStartIncluding":"3.10.0","versionEndExcluding":"3.16.10"},{"versionStartIncluding":"4.0.0","versionEndExcluding":"4.2.6"},{"versionStartIncluding":"4.0.0","versionEndExcluding":"4.2.6"},{"versionStartIncluding":"4.3.0","versionEndExcluding":"4.3.5"},{"versionStartIncluding":"4.3.0","versionEndExcluding":"4.3.5"},{"versionStartIncluding":"4.4.0","versionEndExcluding":"4.4.3"},{"versionStartIncluding":"4.4.0","versionEndExcluding":"4.4.3"},{"versionStartIncluding":"4.5.0","versionEndExcluding":"4.5.1"},{"versionStartIncluding":"4.5.0","versionEndExcluding":"4.5.1"}]},{"advisory":{"name":"Jira Service Desk Security Advisory 2019-11-06","url":"https://confluence.atlassian.com/adminjiraserver/jira-service-desk-security-advisory-2019-11-06-1047539905.html"},"cveId":"CVE-2019-15004","description":"The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, and from 4.5.0 before 4.5.1 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via a path traversal vulnerability. Note that when the 'Anyone can email the service desk or raise a request in the portal' setting is enabled, an attacker can grant themselves portal access, allowing them to exploit the vulnerability.","baseScore":7.5,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"3.9.17"},{"versionStartIncluding":null,"versionEndExcluding":"3.9.17"},{"versionStartIncluding":"3.10.0","versionEndExcluding":"3.16.10"},{"versionStartIncluding":"3.10.0","versionEndExcluding":"3.16.10"},{"versionStartIncluding":"4.0.0","versionEndExcluding":"4.2.6"},{"versionStartIncluding":"4.0.0","versionEndExcluding":"4.2.6"},{"versionStartIncluding":"4.3.0","versionEndExcluding":"4.3.5"},{"versionStartIncluding":"4.3.0","versionEndExcluding":"4.3.5"},{"versionStartIncluding":"4.4.0","versionEndExcluding":"4.4.3"},{"versionStartIncluding":"4.4.0","versionEndExcluding":"4.4.3"},{"versionStartIncluding":"4.5.0","versionEndExcluding":"4.5.1"}]},{"advisory":{"name":"Jira Data Center And Jira Service Management Data Center Security Advisory 2021-07-21","url":"https://confluence.atlassian.com/adminjiraserver/jira-data-center-and-jira-service-management-data-center-security-advisory-2021-07-21-1063571388.html"},"cveId":"CVE-2020-36239","description":"Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache RMI network service which attackers, who can connect to the service, on port 40001 and potentially 40011[0][1], could execute arbitrary code of their choice in Jira through deserialization due to a missing authentication vulnerability. While Atlassian strongly suggests restricting access to the Ehcache ports to only Data Center instances, fixed versions of Jira will now require a shared secret in order to allow access to the Ehcache service. [0] In Jira Data Center, Jira Core Data Center, and Jira Software Data Center versions prior to 7.13.1, the Ehcache object port can be randomly allocated. [1] In Jira Service Management Data Center versions prior to 3.16.1, the Ehcache object port can be randomly allocated.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":"2.0.2","versionEndExcluding":"4.5.16"},{"versionStartIncluding":"4.6.0","versionEndExcluding":"4.13.8"},{"versionStartIncluding":"4.14.0","versionEndExcluding":"4.17.0"}]},{"advisory":{"name":"Multiple Products Security Advisory - Unrendered unicode bidirectional override characters - CVE-2021-42574","url":"https://confluence.atlassian.com/display/SECURITY/Multiple+Products+Security+Advisory+-+Unrendered+unicode+bidirectional+override+characters+-+CVE-2021-42574"},"cveId":"CVE-2021-42574","description":"An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard and the Unicode Bidirectional Algorithm (all versions). Due to text display behavior when text includes left-to-right and right-to-left characters, the visual order of tokens may be different from their logical order. Additionally, control characters needed to fully support the requirements of bidirectional text can further obfuscate the logical order of tokens. Unless mitigated, an adversary could craft source code such that the ordering of tokens perceived by human reviewers does not match what will be processed by a compiler/interpreter/etc. The Unicode Consortium has documented this class of vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms, and in Unicode Standard Annex #31, Unicode Identifier and Pattern Syntax. Also, the BIDI specification allows applications to tailor the implementation in ways that can mitigate misleading visual reordering in program text; see HL4 in Unicode Standard Annex #9, Unicode Bidirectional Algorithm.","baseScore":8.3,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"4.13.13"},{"versionStartIncluding":"4.14.0","versionEndExcluding":"4.19.2"},{"versionStartIncluding":"4.20.0","versionEndExcluding":"4.20.1"}]},{"advisory":{"name":"Jira Security Advisory 2022-04-20","url":"https://confluence.atlassian.com/display/JIRA/Jira+Security+Advisory+2022-04-20"},"cveId":"CVE-2022-0540","description":"A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Management Server and Data Center versions before 4.13.18, versions 4.14.0 and later before 4.20.6, and versions 4.21.0 and later before 4.22.0.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"4.13.18"},{"versionStartIncluding":"4.14.0","versionEndExcluding":"4.20.6"},{"versionStartIncluding":"4.21.0","versionEndExcluding":"4.22.0"}]},{"advisory":{"name":"CVE-2022-1471 - SnakeYAML library RCE Vulnerability impacts Multiple Products","url":"https://confluence.atlassian.com/security/cve-2022-1471-snakeyaml-library-rce-vulnerability-impacts-multiple-products-1296171009.html"},"cveId":"CVE-2022-1471","description":"SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":"5.4.0","versionEndExcluding":"5.4.14"},{"versionStartIncluding":"5.5.0","versionEndExcluding":"5.11.2"}]},{"advisory":{"name":"Multiple Products Security Advisory - CVE-2022-26136, CVE-2022-26137","url":"https://confluence.atlassian.com/security/multiple-products-security-advisory-cve-2022-26136-cve-2022-26137-1141493031.html"},"cveId":"CVE-2022-26136","description":"A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4.","baseScore":9.8,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"4.13.22"},{"versionStartIncluding":"4.14.0","versionEndExcluding":"4.20.10"},{"versionStartIncluding":"4.21.0","versionEndExcluding":"4.22.4"}]},{"advisory":{"name":"Multiple Products Security Advisory - CVE-2022-26136, CVE-2022-26137","url":"https://confluence.atlassian.com/security/multiple-products-security-advisory-cve-2022-26136-cve-2022-26137-1141493031.html"},"cveId":"CVE-2022-26137","description":"A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim’s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4.","baseScore":8.8,"cpeMatches":[{"versionStartIncluding":null,"versionEndExcluding":"4.13.22"},{"versionStartIncluding":"4.14.0","versionEndExcluding":"4.20.10"},{"versionStartIncluding":"4.21.0","versionEndExcluding":"4.22.4"}]},{"advisory":{"name":"Jira Service Management Server and Data Center Security Advisory (CVE-2023-22501)","url":"https://confluence.atlassian.com/jira/jira-service-management-server-and-data-center-advisory-2023-02-01-1188786458.html"},"cveId":"CVE-2023-22501","description":"An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and outgoing email enabled on a Jira Service Management instance, an attacker could gain access to signup tokens sent to users with accounts that have never been logged into. Access to these tokens can be obtained in two cases: * If the attacker is included on Jira issues or requests with these users, or * If the attacker is forwarded or otherwise gains access to emails containing a “View Request” link from these users. Bot accounts are particularly susceptible to this scenario. On instances with single sign-on, external customer accounts can be affected in projects where anyone can create their own account.","baseScore":9.1,"cpeMatches":[{"versionStartIncluding":"5.3.0","versionEndExcluding":"5.3.3"},{"versionStartIncluding":"5.4.0","versionEndExcluding":"5.4.2"},{"versionStartIncluding":"5.5.0","versionEndExcluding":"5.5.1"}]}]
