668
VMScore

CVE-2020-36239

Published: 29/07/2021 Updated: 01/08/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 prior to 8.5.16, from 8.6.0 prior to 8.13.8, from 8.14.0 prior to 8.17.0 and Jira Service Management Data Center from version 2.0.2 prior to 4.5.16, from version 4.6.0 prior to 4.13.8, and from version 4.14.0 prior to 4.17.0 exposed a Ehcache RMI network service which attackers, who can connect to the service, on port 40001 and potentially 40011[0][1], could execute arbitrary code of their choice in Jira through deserialization due to a missing authentication vulnerability. While Atlassian strongly suggests restricting access to the Ehcache ports to only Data Center instances, fixed versions of Jira will now require a shared secret in order to allow access to the Ehcache service. [0] In Jira Data Center, Jira Core Data Center, and Jira Software Data Center versions prior to 7.13.1, the Ehcache object port can be randomly allocated. [1] In Jira Service Management Data Center versions prior to 3.16.1, the Ehcache object port can be randomly allocated.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

atlassian jira data center

atlassian jira service desk

atlassian jira service management

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> ATLASSIAN - CVE-2020-36239 - Jira Data Center and Jira Service Management Data Center <!--X-Subject-Header-End--> <!-- ...

Github Repositories

Hi there 👋, I am J0hNs0N 🔭 JOB: Security Researcher 🌱 I’m currently learning PHP Java Python Go now ✨ Gitee: giteecom/J0hNs0N 📖Latest blog posts LinkWechat 基于企业微信的 SCRM 系统 一次对在线文档预览的JAVA代码审计 Django 安全开发小记 一次简单的Java代码审计 CVE-2020-36239 - Jira 多款产品RCE漏洞分析