6.5
CVSSv2

CVE-2021-26077

Published: 10/05/2021 Updated: 18/05/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Broken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 prior to 2.1.3 and from version 2.1.4 prior to 2.1.5: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Spring Boot app occurs with a server-to-server JWT or a context JWT. Atlassian Connect Spring Boot versions 1.1.0 prior to 2.1.3 and versions 2.1.4 prior to 2.1.5 erroneously accept context JWTs in lifecycle endpoints (such as installation) where only server-to-server JWTs should be accepted, permitting an malicious user to send authenticated re-installation events to an app.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product