Uploaded image for project: 'SR for Jira - Development'
  1. SR for Jira - Development
  2. SRJIRA-5647

Security issue in expression JQL function

XMLWordPrintableJSON

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Critical Critical
    • 6.40.0
    • None
    • None
    • None
    • SR4J Sprint 112
    • 0

      A vulnerability exists within the Scriptrunner expression() JQL function which could allow access to files on the file systems to a user without permission. Most Jira instances will have restrictions on who can run JQL Queries, but in the worst case Jira could be configured to allow anonymous access.

      As mitigation the 'expression' and 'aggregateExpression' functions plugin module can be disabled through Manage Apps:

      • Scripted JQL Function - expression (scripted-jql-function-expression)
      • Scripted JQL Function - aggregateExpression (scripted-jql-function-aggregateExpression)

            jechlin Jamie Echlin
            jechlin Jamie Echlin
            Votes:
            0 Vote for this issue
            Watchers:
            15 Start watching this issue

              Created:
              Updated:
              Resolved: