Improper Authentication in Atlassian Jira Server and Data Center
CVE-2021-41312

7.5HIGH

Key Information:

Vendor

Atlassian

Vendor
CVE Published:
3 November 2021

What is CVE-2021-41312?

A vulnerability in Atlassian Jira Server and Data Center permits a remote attacker, who previously had their access revoked from Jira Service Management, to manipulate Issue Collectors within Jira Service Management projects. This is achieved via an improper authentication flaw found in the /secure/ViewCollectors endpoint. The issue affects all versions prior to 8.19.1, potentially compromising project settings and causing unauthorized control over issue tracking elements.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Jira Data Center < 8.19.1

Jira Server < 8.19.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.