CVE Database
/

CVE-2021-26073

Back to search

CVE-2021-26073

Published: Apr 16, 2021

Modified: Feb 12, 2025

PUBLISHED

Description

Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Express app occurs with a server-to-server JWT or a context JWT. Atlassian Connect Express versions from 3.0.2 before 6.6.0 erroneously accept context JWTs in lifecycle endpoints (such as installation) where only server-to-server JWTs should be accepted, permitting an attacker to send authenticated re-installation events to an app.

VendorProductVersions

Atlassian

Atlassian Connect Express (ACE)

affected
3.0.2 - < unspecified
affected
unspecified - < 6.6.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now