Improper Authentication in Atlassian Jira Server and Data Center
CVE-2021-41312
7.5HIGH
Key Information:
- Vendor
Atlassian
- Vendor
- CVE Published:
- 3 November 2021
What is CVE-2021-41312?
A vulnerability in Atlassian Jira Server and Data Center permits a remote attacker, who previously had their access revoked from Jira Service Management, to manipulate Issue Collectors within Jira Service Management projects. This is achieved via an improper authentication flaw found in the /secure/ViewCollectors endpoint. The issue affects all versions prior to 8.19.1, potentially compromising project settings and causing unauthorized control over issue tracking elements.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jira Data Center < 8.19.1
Jira Server < 8.19.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved