cbcvebase.
CVE-2017-18104
published 2018-07-24

CVE-2017-18104: The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to observe or…

PriorityP430medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
1.60%
72.9th percentile
The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to observe or otherwise intercept webhook events to learn information about changes in issues that should not be sent because they are not contained within the results of a specified JQL query.

Affected

5 ranges
VendorProductVersion rangeFixed in
atlassianjira< 7.6.77.6.7
atlassianjira>= 7.7.0 < unspecifiedunspecified
atlassianjira>= unspecified < 7.6.77.6.7
atlassianjira>= unspecified < 7.11.07.11.0
atlassianjira_server>= 7.7.0 < 7.11.07.11.0

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.