Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Doubt about CVE-2020-36239

jeferson_furio_itau-unibanco_com_br
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
March 30, 2022

Hello Support. 

 

I'm a security analyst and I work directly with vulnerabilities. According to your text, this vulnerability (CVE-2020-36239 ) only affects the products: Jira Data Center, Jira Core Data Center, Jira Software Data Center and Jira Service Management Data Center.

Our scanner identified the vulnerability CVE-2020-36239. But at this server, it's installed olny the Jira Server. 

I am analyzing if it is a possible false positive, but I would like to verify with you, if there is not the possibility that this vulnerability also affects other products? The affected products (Data Center and Service Management), to my knowledge of Atlassian, it's products that centralizes several other products in the same application, right? 

Thinking about this scenario, I imagine that there is sharing of resources, libraries and applications between products, for example, between the Jira Core Data Center and Jira Server. And if what I am reporting is correct, then there is a possibility that this vulnerability affects other products.

Our scanner identified other vulnerabilities: 

CVE-2021-39128, CVE-2017-18113, CVE-2021-39123, CVE-2021-39112, CVE-2021-39118, CVE-2021-39122, CVE-2021-39119, CVE-2021-39113, CVE-2021-26081, CVE-2021-26086, CVE-2020-36289, CVE-2020-36287, CVE-2020-36238, CVE-2020-36286, CVE-2020-36237, CVE-2021-39117, CVE-2021-26082, CVE-2021-26083, CVE-2021-26071, CVE-2021-39116, CVE-2021-39124, CVE-2021-39111, CVE-2021-26080, CVE-2021-26079, CVE-2021-26078, CVE-2020-36288, CVE-2021-39121, CVE-2021-26075 and CVE-2021-26076

And all of then (I checked one by one) it's related always to Jira Server and Jira Data Center.

Only this CVE-2020-36239 it's just for Jira Data Center and Service Management. 

 

Can you guys check please. Any doubts I am available. 

Thank you very much.

 

 

1 answer

1 vote
Trudy Claspill
Community Champion
March 30, 2022

Hello @jeferson_furio_itau-unibanco_com_br 

Welcome to the community.

This is not a support portal for Atlassian. This is a user community.

If you need to contact Atlassian Support directly, you or your Jira Administrators will need to open a support case. That can be done by clicking the Contact Support button at the bottom of this page:

https://support.atlassian.com/

jeferson_furio_itau-unibanco_com_br
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
March 31, 2022

I'm trying to do it myself, but without success. I don't have an administrative account in Jira. This analysis carried out by me, is for a company of the group. When I select the "Contact support" option, it directs me back to the community. I am not able to find an option to send this question for support.

Trudy Claspill
Community Champion
March 31, 2022

It has been several years since i worked with Jira Server. It may be that only the Jira Administrators or specific people from your company are able to create support cases. Work with your Jira Administrators to see if they can help you open a support case.

Suggest an answer

Log in or Sign up to answer