Authentication Vulnerability in Atlassian Jira Data Center Products
CVE-2020-36239
Key Information:
- Vendor
- Atlassian
- Status
- Vendor
- CVE Published:
- 29 July 2021
Summary
The vulnerability involves the exposure of the Ehcache RMI network service in several versions of Jira Data Center and related products. It allows attackers to execute arbitrary code by deserializing data sent over the network to the vulnerable Ehcache ports. Attackers capable of connecting to these ports can gain unauthorized access, potentially leading to significant compromises of Jira instances. Atlassian recommends that users restrict access to these ports and highlights that newer versions now require a shared secret for Ehcache service access to mitigate this security risk.
Affected Version(s)
Jira Core Data Center 6.3.0
Jira Core Data Center < 8.5.16
Jira Core Data Center 8.6.0
References
EPSS Score
20% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved