First published: Thu Jan 03 2008(Updated: )
The Setup Wizard in Atlassian JIRA Enterprise Edition before 3.12.1 does not properly restrict setup attempts after setup is complete, which allows remote attackers to change the default language.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian JIRA | <=3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6619 is considered a moderate severity vulnerability due to its potential for unauthorized language changes.
To fix CVE-2007-6619, upgrade Atlassian JIRA Enterprise Edition to version 3.12.1 or later.
CVE-2007-6619 affects Atlassian JIRA Enterprise Edition versions prior to 3.12.1.
Yes, CVE-2007-6619 can be exploited remotely by attackers without needing authentication.
The impact of CVE-2007-6619 is that attackers can change the default language setting in JIRA after initial setup.