A critical vulnerability was fixed this week in Jira Service Management Server, a popular IT services management platform for enterprises, that could allow attackers to impersonate users and gain access to access tokens. If the system is configured to allow public sign-up, external customers can be affected as well.
The bug was introduced in Jira Service Management Server and Data Center 5.3.0, so versions 5.3.0 to 5.3.1 and 5.4.0 to 5.5.0 are affected. Atlassian has released fixed versions of the software but has also provided a workaround that involves updating a single JAR file in impacted deployments. Atlassian Cloud instances are not vulnerable.
More Stories
Researchers warn of two new variants of potent IcedID malware loader
Monopolist Service Model Enrages Tesla Owners : $29K Bill for Minor Damage and No Delivery Date
7 Reasons Why You Should Get CMMC Certified Ahead of the May 2023 Rulemaking