Elements Copy & Sync

2026/10/06 - Security improvements

This security issue was fixed on .

Nature of the issue

A security vulnerability has been recently identified in Elements Copy & Sync. The vulnerability affected version 12.0.0 of the app. The vulnerability meant that Elements Copy & Sync API admin token could be exfiltrated without authorization from to .

This vulnerability has been rated as high, according to the scale published on the Common Vulnerability Scoring System (CVSS).

This vulnerability was responsibly disclosed through our Bug Bounty program. It resulted from a configuration setting in our app, combined with a behavior of the Forge platform that has since been addressed by Atlassian. We have corrected our configuration, and the issue is fully resolved.

Impact

Based on our investigation, this vulnerability allowed a Jira user with access to a project where the Elements Copy & Sync issue panel is displayed to obtain an application session token. No Jira administration rights or action from a site administrator were required.

With that token, a user could:

  • create or delete Elements Copy & Sync recipes, affecting what content is copied and where it is sent

  • generate a new app REST API token, replacing the existing API credential

  • initiate remote instance pairing requests

  • read app configuration, including the projects and spaces referenced by each recipe

The only prerequisite was access to at least one Jira project where the Copy & Sync issue panel is displayed. Depending on how the app is configured, this may include employees, contractors, and partners with Jira access.

Analysis and actions taken

Once we became aware of the issue, we reproduced it and identified the root cause. The Copy & Sync manifest was configured to attach an application token to requests sent to the Copy & Sync REST APIs. Under certain conditions, those requests could be accessed/reused outside of their intended context, which exposed an unintended attack surface. Atlassian has since addressed this behavior on the Forge platform, and we have updated our manifest configuration so that the application token is no longer included in these requests.

This vulnerability is now fixed.

We've updated the Atlassian Marketplace with an updated listing of our app that is free from this vulnerability.

No further action is required from any user at this point.

Conclusion

We want you to know that we take this issue very seriously. We are conducting a thorough review of our internal processes to ensure this does not occur again for you and our other customers.

If you have any questions, please feel free to raise a support request at support.elements-apps.com.