Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Atlassian JIRA < 3.12.1 Multiple Vulnerabilities

Medium

Synopsis

The remote web server contains an application that is affected by one or more vulnerabilities.

Description

Atlassian JIRA, a web-based application for bug tracking, issue tracking and project management, installed on the remote web server is affected by one or more of the following issues :

- A cross-site scripting issue due to its failure to sanitize error messages under a user's control and passed to the '500page.jsp' script before using them to generate dynamic output.

- A security bypass issue that may allow an attacker to change JIRA's default language by accessing its first setup page directly.

- A security bypass issue by which a user may delete a shared filter created by another user.

Solution

Upgrade to version 3.12.1 or higher or patch according to vendor recommendations.