CVE-2020-36239 - CVE House
Back to Database
Status published Unknown CVE-2020-36239

Jira Data Center, Jira Core Data Center, Jira Software Data...

Vulnerability Description

Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache RMI network service which attackers, who can connect to the service, on port 40001 and potentially 40011[0][1], could execute arbitrary code of their choice in Jira through deserialization due to a missing authentication vulnerability. While Atlassian strongly suggests restricting access to the Ehcache ports to only Data Center instances, fixed versions of Jira will now require a shared secret in order to allow access to the Ehcache service. [0] In Jira Data Center, Jira Core Data Center, and Jira Software Data Center versions prior to 7.13.1, the Ehcache object port can be randomly allocated. [1] In Jira Service Management Data Center versions prior to 3.16.1, the Ehcache object port can be randomly allocated.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-36239

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Jira Data Center, Jira Core Data Center, Jira Software Data Center, Jira Service Management Data Center
Vulnerable Versions:
6.3.0, unspecified, 8.6.0, 8.14.0, 2.0.2, 4.6.0, 4.14.0

Timeline

Official Publish: July 29th, 2021
Last Modified: October 17th, 2024
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)