TROYANOSYVIRUS
Retour aux CVEs

CVE-2017-18101

MEDIUM
6.5

Description

Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7.6.5, from version 7.7.0 before version 7.7.3, from version 7.8.0 before version 7.8.3 and before version 7.9.0 allow remote attackers to run import operations and to determine if an internal service exists through missing permission checks.

Details CVE

Score CVSS v3.16.5
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie4/10/2018
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

atlassian:jiraatlassian:jira_server

Faiblesses (CWE)

CWE-284CWE-862

References

http://www.securityfocus.com/bid/103730(af854a3a-2127-422b-91ae-364da2661108)
https://jira.atlassian.com/browse/JRASERVER-67107(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.