SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-13404

The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from…

MEDIUM 4.1EPSS 1.14%

Does this matter?

Lower severity and a low EPSS score (1.14%). Track it; it rarely justifies an emergency change on its own.

Description

The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and from version 7.13.0 before version 7.13.1 allows remote attackers who have administrator rights to determine the existence of internal hosts & open ports and in some cases obtain service information from internal network resources via a Server Side Request Forgery (SSRF) vulnerability.

CVSS 3.0
4.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
EPSS
1.14% probability · 65th percentile
CISA KEV
Not listed
Weakness
CWE-918
Affected
atlassian/jira · atlassian/jira server
Source
security@atlassian.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.