Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2022-06112

Опубликовано: 25 фев. 2022
Источник: fstec
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Уязвимость программных продуктов обработки данных Atlassian Jira, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Fisheye и Crucible связана с неправильным порядком поведения. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, обойти процедуру аутентификации и проводить межсайтовый скриптинг

Вендор

Atlassian

Наименование ПО

Confluence Server
Bamboo
Bitbucket Data Center
Crowd
Fisheye
Crucible
Jira Service Management
Jira

Версия ПО

до 7.4.17 (Confluence Server)
до 8.0.9 (Bamboo)
от 8.1.0 до 8.1.8 (Bamboo)
от 8.2.0 до 8.2.4 (Bamboo)
до 7.6.16 (Bitbucket Data Center)
от 7.7.0 до 7.17.8 (Bitbucket Data Center)
от 7.18.0 до 7.19.5 (Bitbucket Data Center)
от 7.20.0 до 7.20.2 (Bitbucket Data Center)
от 7.21.0 до 7.21.2 (Bitbucket Data Center)
8.0.0 (Bitbucket Data Center)
8.1.0 (Bitbucket Data Center)
от 7.5. 0 до 7.13.7 (Confluence Server)
от 7.14.0 до 7.14.3 (Confluence Server)
от 7.15.0 до 7.15.2 (Confluence Server)
от 7.16.0 до 7.16.4 (Confluence Server)
от 7.17.0 до 7.17.4 (Confluence Server)
7.21.0 (Confluence Server)
до 4.3.8 (Crowd)
от 4.4.0 до 4.4.2 (Crowd)
5.0.0 (Crowd)
до 4.8.10 (Fisheye)
до 4.8.10 (Crucible)
до 4.13.22 (Jira Service Management)
от 4.14.0 до 4.20.10 (Jira Service Management)
от 4.21.0 до 4.22.4 (Jira Service Management)
до 8.13.22 (Jira)
от 8.14.0 до 8.20.10 (Jira)
от 8.21.0 до 8.22.4 (Jira)

Тип ПО

Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 5)
Средний уровень опасности (базовая оценка CVSS 3.0 составляет 5,3)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://jira.atlassian.com/browse/BAM-21795
https://jira.atlassian.com/browse/BSERV-13370
https://jira.atlassian.com/browse/CONFSERVER-79476
https://jira.atlassian.com/browse/CRUC-8541
https://jira.atlassian.com/browse/CWD-5815
https://jira.atlassian.com/browse/FE-7410
https://jira.atlassian.com/browse/JRASERVER-73897
https://jira.atlassian.com/browse/JSDSERVER-11863

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 41%
0.00183
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
nvd
почти 3 года назад

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atl

CVSS3: 9.8
github
почти 3 года назад

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. ...

EPSS

Процентиль: 41%
0.00183
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2