Vulnerability Description
An issue in Deviniti Issue Sync Synchronization v3.5.2 for Jira allows attackers to obtain the login credentials of a user via a crafted request sent to /rest/synchronizer/1.0/technicalUser.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Deviniti | Issue Sync | < 3.5.2 |
References
- http://deviniti.comProduct
- http://issue.comProduct
- https://github.com/D23K4N/CVE/blob/main/CVE-2023-30285.mdThird Party Advisory
- http://deviniti.comProduct
- http://issue.comProduct
- https://github.com/D23K4N/CVE/blob/main/CVE-2023-30285.mdThird Party Advisory
FAQ
What is CVE-2023-30285?
CVE-2023-30285 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue in Deviniti Issue Sync Synchronization v3.5.2 for Jira allows attackers to obtain the login credentials of a user via a crafted request sent to /rest/synchronizer/1.0/technicalUser.
How severe is CVE-2023-30285?
CVE-2023-30285 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-30285?
Check the references section above for vendor advisories and patch information. Affected products include: Deviniti Issue Sync.