Authentication Vulnerability in Atlassian Jira Data Center Products
CVE-2020-36239

9.8CRITICAL

Key Information:

Summary

The vulnerability involves the exposure of the Ehcache RMI network service in several versions of Jira Data Center and related products. It allows attackers to execute arbitrary code by deserializing data sent over the network to the vulnerable Ehcache ports. Attackers capable of connecting to these ports can gain unauthorized access, potentially leading to significant compromises of Jira instances. Atlassian recommends that users restrict access to these ports and highlights that newer versions now require a shared secret for Ehcache service access to mitigate this security risk.

Affected Version(s)

Jira Core Data Center 6.3.0

Jira Core Data Center < 8.5.16

Jira Core Data Center 8.6.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.