Broken Authentication in Atlassian Jira Server and Data Center
CVE-2021-41309

5.3MEDIUM

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
8 December 2021

Summary

Atlassian Jira Server and Data Center versions prior to 8.19.1 are susceptible to a Broken Authentication vulnerability. This issue arises when a user, who has had their access to Jira Service Management revoked, can exploit the /plugins/servlet/audit/resource endpoint to export audit logs from other users' projects. This risk highlights significant security concerns about user access controls and proper session management.

Affected Version(s)

Jira Data Center < 8.19.1

Jira Server < 8.19.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.