PT-2021-16941 · Atlassian · Connect Spring Boot

CVE-2021-26074

·

Published

2021-04-16

·

Updated

2025-02-12

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Atlassian Connect Spring Boot versions 1.1.0 through 2.1.2
Description The issue concerns broken authentication in Atlassian Connect Spring Boot, a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the app occurs via a server-to-server JWT or a context JWT. However, versions of Atlassian Connect Spring Boot from 1.1.0 before 2.1.3 incorrectly accept context JWTs in lifecycle endpoints, such as installation, where only server-to-server JWTs should be accepted. This allows an attacker to send authenticated re-installation events to an app.
Recommendations For Atlassian Connect Spring Boot versions 1.1.0 through 2.1.2, update to version 2.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to lifecycle endpoints, such as installation, to minimize the risk of exploitation.

Fix

Improper Authentication

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-26074
GHSA-CPCR-74Q9-74GP

Affected Products

Connect Spring Boot