Atlassian JIRA Common Credentials

Critical Nessus Plugin ID 123003

Synopsis

The remote web server is protected using a common set of credentials.

Description

Nessus was able to gain access to the Atlassian JIRA web application using a common set of credentials. A remote attacker can exploit this issue to disclose sensitive information or otherwise affect the operation of the application and underlying system.

Solution

Change or remove the affected set of JIRA credentials.

Plugin Details

Severity: Critical

ID: 123003

File Name: jira_common_creds.nasl

Version: 1.4

Type: remote

Family: CGI abuses

Published: 2019/03/22

Updated: 2020/12/03

Dependencies: 45577

Risk Information

Risk Factor: Critical

CVSS Score Source: manual

CVSS Score Rationale: Tenable score for default credentials.

CVSS v2.0

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS v3.0

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:atlassian:jira

Required KB Items: installed_sw/Atlassian JIRA

Excluded KB Items: global_settings/supplied_logins_only

Exploited by Nessus: true