This security issue was fixed on .
Nature of the issue
A security vulnerability has been recently identified in Elements Copy & Sync. The vulnerability affected version 9.1.0 of the app. The vulnerability meant that Elements Copy & Sync API admin token could be generated, revoked, or replaced without authorization from to .
This vulnerability has been rated as high, according to the scale published on the Common Vulnerability Scoring System (CVSS).
The vulnerability was brought to our attention by the Bug Bounty program.
Impact
Based on our investigation, this vulnerability allowed any licensed Jira user on a site running Elements Copy & Sync to obtain an app-administrator-level session token, without requiring Jira administration rights or any action from a site administrator.
With that token, a user could:
-
create or delete Elements Copy & Sync recipes, affecting what content is copied and where it is sent
-
generate a new app REST API token, replacing the existing API credential
-
initiate remote instance pairing requests
-
read app configuration, including the projects and spaces referenced by each recipe
The only prerequisite was an active Jira licence on the affected site. In most organizations, this includes employees, contractors, and partners with Jira access.
Analysis and actions taken
Once we became aware of the issue, we reproduced and identified the root cause: the app's Copy & Sync REST API endpoint was not validating the origin of incoming requests.
This vulnerability is now fixed.
We've updated the Atlassian Marketplace with an updated listing of our app that is free from this vulnerability.
No further action is required from any user at this point.
Conclusion
We want you to know that we take this issue very seriously. We are conducting a thorough review of our internal processes to ensure this does not occur again for you and our other customers.
If you have any questions, please feel free to raise a support request at support.elements-apps.com.