Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Steps to remediate vulnerability

Krithica G July 9, 2021

Hi,
Below is the vulnerability report we received.
Summary:
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint.

Platform Affected: [website]
https://vzmdev.atlassian.net

Please provide steps to remediate this vulnerability

JIRA Version Used: 8.13

2 answers

1 accepted

1 vote
Answer accepted
Mohamed Benziane
Community Champion
July 9, 2021

Hi,

Take a look on this ticket, you will find some workaround.

https://jira.atlassian.com/browse/JRASERVER-71536

Krithica G July 12, 2021

Thanks

0 votes
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
July 9, 2021

I'm afraid this question is utterly unclear. 

The reason is you say "Platform Affected: [website] https://vzmdev.atlassian.net" and "Jira Version Used: 8.13" which is nonsense because the site is Jira Cloud which is emphatically not running Jira 8.13 Server/DC.

Which one are you really asking about?  Your Cloud site, or a Server install?

Krithica G July 12, 2021

Hi Nic,

Sorry i was not clear with the question. We are using Server jira 8.13 and wanted to know the steps to remediate this vulnerability- Information Disclosure vulnerability

Summary:
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint

Thanks,

Krithica

Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
July 12, 2021

Ok, so the vzmdev.atlassian.net mention is a complete red-herring and has nothing to do with it.

Go with Mohamed's answer!

Krithica G July 12, 2021

ok thank you

Suggest an answer

Log in or Sign up to answer
TAGS
atlassian, team '25 europe, atlassian event, barcelona 2025, jira, confluence, atlassian intelligence, rovo, ai-powered collaboration, developer tools, agile teams, digital transformation, teamwork solutions, atlassian conference, product announcements

🌆 Team '25 Europe registration is now open!

Join the largest European gathering of the Atlassian Community and reimagine what’s possible when great teams and transformative technology come together. Plus, grab your Super Fan ticket now and save over €1,000 on your pass before prices rise on 3 June.

Register now
AUG Leaders

Atlassian Community Events