Source |
CSO |
Identifiant |
8307014 |
Date de publication |
2023-02-03 13:13:00 (vue: 2023-02-03 22:07:49) |
Titre |
Critical vulnerability patched in Jira Service Management Server and Data Center |
Texte |
A critical vulnerability was fixed this week in Jira Service Management Server, a popular IT services management platform for enterprises, that could allow attackers to impersonate users and gain access to access tokens. If the system is configured to allow public sign-up, external customers can be affected as well.The bug was introduced in Jira Service Management Server and Data Center 5.3.0, so versions 5.3.0 to 5.3.1 and 5.4.0 to 5.5.0 are affected. Atlassian has released fixed versions of the software but has also provided a workaround that involves updating a single JAR file in impacted deployments. Atlassian Cloud instances are not vulnerable.To read this article in full, please click here |
Notes |
★★★★
|
Envoyé |
Oui |
Condensat |
access affected allow also are article atlassian attackers bug but can center click cloud configured could critical customers data deployments enterprises external file fixed full gain has here impacted impersonate instances introduced involves jar jira management not patched platform please popular provided public read released server service services sign single software system tokens updating users versions vulnerability vulnerable week well workaround |
Tags |
Vulnerability
|
Stories |
|
Move |
|