First published: Tue Sep 14 2021(Updated: )
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an enumeration vulnerability in the /rest/api/1.0/render endpoint. The affected versions are before version 8.19.0.
Credit: security@atlassian.com security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Data Center | <8.19.0 | |
Atlassian Jira | <8.19.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39118 is a vulnerability in Atlassian Jira Server and Data Center that allows remote attackers to discover the usernames and full names of users.
Remote attackers can exploit CVE-2021-39118 by sending a request to the /rest/api/1.0/render endpoint.
Versions of Atlassian Jira Server and Data Center before version 8.19.0 are affected by CVE-2021-39118.
CVE-2021-39118 has a severity rating of 5.3 (medium).
To fix CVE-2021-39118, you should upgrade your Atlassian Jira Server or Data Center to version 8.19.0 or later.