← Back

CVE-2017-18101

nvd nist
Published: Apr 10, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.5
Source: NVD

Description

Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7.6.5, from version 7.7.0 before version 7.7.3, from version 7.8.0 before version 7.8.3 and before version 7.9.0 allow remote attackers to run import operations and to determine if an internal service exists through missing permission checks.

Affected (3)

2 products
Jira
Jira Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Before 7.6.5
Atlassian
From 7.7.0 to 7.7.3
From 7.8.0 to 7.8.3

References (4)

Source: security@atlassian.com
Broken Link
Source: security@atlassian.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.