Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.
2021-03-22T05:15:13.257
2024-11-21T05:55:48.650
Modified
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:N
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | atlassian | data_center | < 8.13.3 | Yes |
Application | atlassian | data_center | < 8.14.1 | Yes |
Application | atlassian | jira | < 8.13.3 | Yes |
Application | atlassian | jira_server | < 8.14.1 | Yes |