Authentication Vulnerability in Atlassian Jira Data Center Products
CVE-2020-36239
Key Information:
- Vendor
Atlassian
- Status
- Vendor
- CVE Published:
- 29 July 2021
What is CVE-2020-36239?
The vulnerability involves the exposure of the Ehcache RMI network service in several versions of Jira Data Center and related products. It allows attackers to execute arbitrary code by deserializing data sent over the network to the vulnerable Ehcache ports. Attackers capable of connecting to these ports can gain unauthorized access, potentially leading to significant compromises of Jira instances. Atlassian recommends that users restrict access to these ports and highlights that newer versions now require a shared secret for Ehcache service access to mitigate this security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jira Core Data Center 6.3.0
Jira Core Data Center < 8.5.16
Jira Core Data Center 8.6.0
References
EPSS Score
16% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved