CVE-2021-26075: Medium severity atlassian data center vulnerability
The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before 8.13.4, and from version 8.14.0 before 8.15.1 allowed remote authenticated attackers to obtain the full path of the Jira application data directory via an information disclosure vulnerability in the error message when presented with an invalid filename.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-26075?
CVE-2021-26075 is a vulnerability in the Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center.
What is the severity of CVE-2021-26075?
The severity of CVE-2021-26075 is medium with a severity value of 4.3.
How does CVE-2021-26075 affect Atlassian Jira?
CVE-2021-26075 affects Atlassian Jira versions up to 8.5.12.
How does CVE-2021-26075 affect Atlassian Jira Data Center?
CVE-2021-26075 affects Atlassian Jira Data Center versions from 8.6.0 to 8.13.4.
How does CVE-2021-26075 affect Atlassian Jira Server?
CVE-2021-26075 affects Atlassian Jira Server versions from 8.6.0 to 8.13.4.