THREATPORT/VULNERABILITY/CVE-2020-36239
CRITICAL SEVERITY

CVE-2020-36239

Jira Data Center vulnerability

CVSS
9.8
EPSS
48.9%
EPSS pct
99th
Exploited
No known
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache RMI network service which attackers, who can connect to the service, on port 40001 and potentially 40011[0][1], could execute arbitrary code of their choice in Jira through deserialization due to a missing authentication vulnerability. While Atlassian strongly suggests restricting access to the Ehcache ports to only Data Center instances, fixed versions of Jira will now require a shared secret in order to allow access to the Ehcache service. [0] In Jira Data Center, Jira Core Data Center, and Jira Software Data Center versions prior to 7.13.1, the Ehcache object port can be randomly allocated. [1] In Jira Service Management Data Center versions prior to 3.16.1, the Ehcache object port can be randomly allocated.
Affected vendor
Atlassian
Affected product
Jira Data Center
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)
  • CWE-862 — Missing Authorization
  • CWE-306 — Missing Authentication for Critical Function
Published
2021-07-29

Risk analysis

Based on its CVSS vector, this vulnerability is exploitable over the network, low attack complexity, requiring no privileges, no user interaction. Successful exploitation leads to high impact to confidentiality, high impact to integrity, high impact to availability.

Its EPSS score of 48.9% reflects a moderate probability of exploitation activity in the wild over the next 30 days, placing it among the most exploited CVEs currently tracked.

Check your external exposure to CVE-2020-36239

  • Confirm whether Atlassian Jira Data Center is running on any internet-facing host or subdomain.
  • Match discovered service fingerprints against the version affected by CVE-2020-36239.
  • Prioritise remediation if the asset is public, business-critical, or near authentication/payment flows.

How ThreatPort helps with CVE-2020-36239

ThreatPort's external attack surface scanner checks your internet-facing assets — agentlessly, from the outside in — for the exposed services and versions that CVE-2020-36239 affects, then prioritises the finding by real risk using CISA KEV and FIRST.org EPSS.

Run a free external exposure scan

Are you exposed to CVE-2020-36239?

Run an instant, non-intrusive external scan to check your attack surface for CVE-2020-36239.

Start free scan

No credit card. Agentless.