Atlassian JIRA Common Credentials

critical Nessus Plugin ID 123003

Synopsis

The remote web server is protected using a common set of credentials.

Description

Nessus was able to gain access to the Atlassian JIRA web application using a common set of credentials. A remote attacker can exploit this issue to disclose sensitive information or otherwise affect the operation of the application and underlying system.

Solution

Change or remove the affected set of JIRA credentials.

Plugin Details

Severity: Critical

ID: 123003

File Name: jira_common_creds.nasl

Version: 1.5

Type: remote

Family: CGI abuses

Published: 3/22/2019

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

CVSS Score Rationale: Tenable score for default credentials.

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: manual

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:atlassian:jira

Required KB Items: installed_sw/Atlassian JIRA

Excluded KB Items: global_settings/supplied_logins_only

Exploited by Nessus: true