This week, Atlassian warned of a critical-severity authentication vulnerability in Jira Service Management Server and Data Center that could allow malicious actors to impersonate Jira users. If an attacker has write access to a User Directory and outgoing email is enabled on a Jira Service Management instance, they can gain access to signup tokens sent to users with accounts that have never been logged into. This can be done by obtaining tokens included in Jira issues or requests with these users, or by obtaining emails containing View Request links from these users. Bot accounts and external customer accounts on instances with single sign-on may also be affected if account creation is open to anyone. Patches for this vulnerability have been released in Jira Service Management Server and Data Center versions 5.3.3, 5.4.2, 5.5.1, and 5.6.0, and users are encouraged to update their Jira installations as soon as possible. This vulnerability does not affect Jira sites hosted by Atlassian and accessed via an atlassian.net domain.
This Cyber News was published on www.securityweek.com. Publication date: Fri, 03 Feb 2023 16:55:03 +0000