
Several malfunctioning Jira servers have leaked information about internal projects and users at Google, NASA, Yahoo , and more, according to a report from Bleeping Computer.
The popular project management program Jira was developed by Atlassian and is used by Fortune 500 companies to monitor the progress of various projects and issues.
The latest revelation, however, shows that anyone with a good knowledge of advanced searchcan gain access to sensitive information through the dysfunctional Jira servers.
The data leak includes names, positions, and email addresses of employees participating in various projects within an organization, along with the current status and progress of those projects.
Malfunctioning Jira server
The leak was caused by a setting in the Jira servers, which is used for the “visibility control of filters and dashboards.”»
Avinash Jain, the security who discovered the leak, found that whenever a new filter or dashboard is created in Jira Cloud, the default visibility is set to “everyone.” While the “everyone” option is interpreted as “everyone within the organization,” it actually refers to everyone on the internet.
Visibility issues
There is a provision in Jira Cloud where programs can be created for anonymous access, meaning a user does not need to log in.
There is a sharing option for filters and dashboards called “Public” that comes with a disclaimer:
“If a filter or dashboard is shared publicly, the name of the filter or dashboard will be visible to anonymous users.”
Another issue is another setting in the Global Permissions menu, where the administrator can select the “Anyone” option to grant access to anonymous users.
For systems that can be made accessible from the public internet, this option is not recommended – because Jira has a selection feature that will allow a user with unlimited access to retrieve a “full list of usernames and email addresses from the servers.”
Bleeping Computer discovered information from several government domains, along with domains of private companies and educational institutions, using this setting.
Depending on the organization and the value of the information, this gap can be used for attack or corporate espionage.
