CVE-2021-39118: Medium severity Atlassian Data Center vulnerability
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an enumeration vulnerability in the /rest/api/1.0/render endpoint. The affected versions are before version 8.19.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.19.0
Event History
Frequently Asked Questions
What is CVE-2021-39118?
CVE-2021-39118 is a vulnerability in Atlassian Jira Server and Data Center that allows remote attackers to discover the usernames and full names of users.
How can remote attackers exploit CVE-2021-39118?
Remote attackers can exploit CVE-2021-39118 by sending a request to the /rest/api/1.0/render endpoint.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2021-39118?
Versions of Atlassian Jira Server and Data Center before version 8.19.0 are affected by CVE-2021-39118.
What is the severity rating of CVE-2021-39118?
CVE-2021-39118 has a severity rating of 5.3 (medium).
How can I fix CVE-2021-39118?
To fix CVE-2021-39118, you should upgrade your Atlassian Jira Server or Data Center to version 8.19.0 or later.