CVE-2021-39119: Medium severity Atlassian Data Center vulnerability
Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature. The affected versions are before version 8.19.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.19.0
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-39119.
What are the affected versions of Atlassian Jira Server and Data Center?
The affected versions of Atlassian Jira Server and Data Center are before version 8.19.0.
What is the severity of CVE-2021-39119?
The severity of CVE-2021-39119 is medium.
How does CVE-2021-39119 affect users who have watched an issue?
CVE-2021-39119 allows users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked.
Is there a fix available for CVE-2021-39119?
Yes, upgrading to version 8.19.0 or later of Atlassian Jira Server and Data Center fixes CVE-2021-39119.