Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Steps to remediate vulnerability

Krithica G July 9, 2021

Hi,
Below is the vulnerability report we received.
Summary:
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint.

Platform Affected: [website]
https://vzmdev.atlassian.net

Please provide steps to remediate this vulnerability

JIRA Version Used: 8.13

2 answers

1 accepted

1 vote
Answer accepted
Mohamed Benziane
Community Champion
July 9, 2021

Hi,

Take a look on this ticket, you will find some workaround.

https://jira.atlassian.com/browse/JRASERVER-71536

Krithica G July 12, 2021

Thanks

0 votes
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
July 9, 2021

I'm afraid this question is utterly unclear. 

The reason is you say "Platform Affected: [website] https://vzmdev.atlassian.net" and "Jira Version Used: 8.13" which is nonsense because the site is Jira Cloud which is emphatically not running Jira 8.13 Server/DC.

Which one are you really asking about?  Your Cloud site, or a Server install?

Krithica G July 12, 2021

Hi Nic,

Sorry i was not clear with the question. We are using Server jira 8.13 and wanted to know the steps to remediate this vulnerability- Information Disclosure vulnerability

Summary:
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint

Thanks,

Krithica

Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
July 12, 2021

Ok, so the vzmdev.atlassian.net mention is a complete red-herring and has nothing to do with it.

Go with Mohamed's answer!

Krithica G July 12, 2021

ok thank you

Suggest an answer

Log in or Sign up to answer