CVE Database
/

CVE-2020-36239

Back to search

CVE-2020-36239

Published: Jul 29, 2021

Modified: Oct 17, 2024

PUBLISHED

Description

Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache RMI network service which attackers, who can connect to the service, on port 40001 and potentially 40011[0][1], could execute arbitrary code of their choice in Jira through deserialization due to a missing authentication vulnerability. While Atlassian strongly suggests restricting access to the Ehcache ports to only Data Center instances, fixed versions of Jira will now require a shared secret in order to allow access to the Ehcache service. [0] In Jira Data Center, Jira Core Data Center, and Jira Software Data Center versions prior to 7.13.1, the Ehcache object port can be randomly allocated. [1] In Jira Service Management Data Center versions prior to 3.16.1, the Ehcache object port can be randomly allocated.

VendorProductVersions

Atlassian

Jira Data Center

affected
6.3.0 - < unspecified
affected
unspecified - < 8.5.16
affected
8.6.0 - < unspecified
affected
unspecified - < 8.13.8
affected
8.14.0 - < unspecified

+1 more versions

Atlassian

Jira Core Data Center

affected
6.3.0 - < unspecified
affected
unspecified - < 8.5.16
affected
8.6.0 - < unspecified
affected
unspecified - < 8.13.8
affected
8.14.0 - < unspecified

+1 more versions

Atlassian

Jira Software Data Center

affected
6.3.0 - < unspecified
affected
unspecified - < 8.5.16
affected
8.6.0 - < unspecified
affected
unspecified - < 8.13.8
affected
8.14.0 - < unspecified

+1 more versions

Atlassian

Jira Service Management Data Center

affected
2.0.2 - < unspecified
affected
unspecified - < 4.5.16
affected
4.6.0 - < unspecified
affected
unspecified - < 4.13.8
affected
4.14.0 - < unspecified

+1 more versions

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now