CVE-2021-26070: High severity Atlassian Data Center vulnerability
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the makeRequest gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-26070.
What is the severity rating of CVE-2021-26070?
The severity rating of CVE-2021-26070 is 7.2 (high).
Which versions of Atlassian Jira Server and Data Center are affected?
Affected versions of Atlassian Jira Server and Data Center are before version 8.13.3 and from version 8.14.0 to 8.14.1.
How can remote attackers exploit this vulnerability?
Remote attackers can exploit this vulnerability to bypass behind-the-firewall protection and access app-linked resources.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at: https://jira.atlassian.com/browse/JRASERVER-72029.