CVE-2007-6619: High severity Atlassian Jira vulnerability
Published Jan 3, 2008
·Updated
The Setup Wizard in Atlassian JIRA Enterprise Edition before 3.12.1 does not properly restrict setup attempts after setup is complete, which allows remote attackers to change the default language.
Affected Software
1 affected component
Atlassian Jira<=3.12
Remediation
Patch Available
Event History
Jan 3, 2008
CVE Published
11:46 PM
Jan 4, 2008
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6619?
CVE-2007-6619 is considered a moderate severity vulnerability due to its potential for unauthorized language changes.
2
How do I fix CVE-2007-6619?
To fix CVE-2007-6619, upgrade Atlassian JIRA Enterprise Edition to version 3.12.1 or later.
3
What systems are affected by CVE-2007-6619?
CVE-2007-6619 affects Atlassian JIRA Enterprise Edition versions prior to 3.12.1.
4
Can CVE-2007-6619 be exploited remotely?
Yes, CVE-2007-6619 can be exploited remotely by attackers without needing authentication.
5
What impact does CVE-2007-6619 have on my JIRA installation?
The impact of CVE-2007-6619 is that attackers can change the default language setting in JIRA after initial setup.