CVE-2021-39113: High severity Atlassian Data Center vulnerability
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions are before version 8.13.9, and from version 8.14.0 before 8.18.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.13.9 - Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.18.0
Event History
Frequently Asked Questions
What is the vulnerability ID of the Atlassian Jira Server and Data Center vulnerability?
The vulnerability ID is CVE-2021-39113.
What is the severity of CVE-2021-39113?
The severity of CVE-2021-39113 is high with a CVSS score of 7.5.
What is the affected software?
The affected software includes Atlassian Jira Server and Data Center versions before 8.13.9, and versions from 8.14.0 to 8.18.0.
What is the impact of the vulnerability?
The vulnerability allows anonymous remote attackers to continue viewing cached content even after losing permissions.
Is there a fix for CVE-2021-39113?
Yes, the fix for CVE-2021-39113 is available in version 8.13.9 of Atlassian Jira Server and Data Center.