CVE-2021-39121: Medium severity Atlassian Data Center vulnerability
Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projects via an Information Disclosure vulnerability in the /rest/api/latest/projectvalidate/key endpoint. The affected versions are before version 8.5.18, from version 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.5.18 - Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.13.10 - Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.18.2
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-39121.
What is the severity of CVE-2021-39121?
The severity of CVE-2021-39121 is medium with a severity value of 4.3.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2021-39121?
Affected versions of Atlassian Jira Server and Data Center are before version 8.5.18, from version 8.6.0 to 8.13.10, and from version 8.14.0 to 8.18.2.
How can an authenticated remote attacker exploit CVE-2021-39121?
An authenticated remote attacker can exploit CVE-2021-39121 by enumerating the keys of private Jira projects via an Information Disclosure vulnerability in the /rest/api/latest/projectvalidate/key endpoint.
Is there a reference for CVE-2021-39121?
Yes, you can find the reference for CVE-2021-39121 at https://jira.atlassian.com/browse/JRASERVER-72715.