Vulnerability CVE-2019-11583


Published: 2019-06-26

Description:
The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name".

Type:

CWE-284

(Improper Access Control)

Vendor: Atlassian
Product: JIRA 
Version:
8.0.2
8.0.1
8.0.0
7.9.2
7.9.1
7.9.0
7.8.4
7.8.3
7.8.2
7.8.1
7.8.0
7.7.4
7.7.3
7.7.2
7.7.1
7.7.0
7.6.9
7.6.8
7.6.7
7.6.6
7.6.5
7.6.4
7.6.3
7.6.2
7.6.11
7.6.10
7.6.1
7.6.0
7.5.4
7.5.3
7.5.2
7.5.1
7.5.0
7.4.6
7.4.5
7.4.4
7.4.3
7.4.2
7.4.1
7.4.0
7.3.9
7.3.8
7.3.7
7.3.6
7.3.5
7.3.4
7.3.3
7.3.2
7.3.1
7.3.0
7.2.9
7.2.8
7.2.7
7.2.6
7.2.5
7.2.4
7.2.3
7.2.2
7.2.15
7.2.14
7.2.13
7.2.12
7.2.11
7.2.10
7.2.1
7.2.0
7.13.2
7.13.1
7.13.0
7.12.3
7.12.2
7.12.1
7.12.0
7.11.3
7.11.2
7.11.1
7.11.0
7.10.2
7.10.1
7.10.0
7.1.9
7.1.8
7.1.7
7.1.6
7.1.4
7.1.2
7.1.10
7.1.1
7.1.0
7.0.9
7.0.5
7.0.4
7.0.3
7.0.2
7.0.11
7.0.10_
7.0.0
6.4.9
6.4.8
6.4.7
See more versions on NVD

CVSS2 => (AV:N/AC:L/Au:S/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial

 References:
http://www.securityfocus.com/bid/108901
https://jira.atlassian.com/browse/JSWSERVER-20111

Related CVE
CVE-2019-15001
The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.1.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote at...
CVE-2019-15000
The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 before 6.1.8 (the fixed version for 6.1.x), from 6.2.0 before 6.2.6 (...
CVE-2019-14994
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, fr...
CVE-2019-8451
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist ...
CVE-2019-8450
Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 allow remote attackers who have permission to manage custom fields to inject arbitrary HTML or JavaScript via a cross site scripti...
CVE-2019-8449
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
CVE-2019-14998
The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via "cookie tossing" a CSRF cookie from a subdomain of a Jira instance.
CVE-2019-14997
The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Prox...

Copyright 2019, cxsecurity.com

 

Back to Top