CVE-2021-39122: Medium severity Atlassian Data Center vulnerability
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view users' emails via an Information Disclosure vulnerability in the /rest/api/2/search endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.5.13 - Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.13.5 - Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.15.1
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-39122.
What is the severity of CVE-2021-39122?
The severity of CVE-2021-39122 is medium with a severity value of 5.3.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2021-39122?
The affected versions of Atlassian Jira Server and Data Center are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 to version 8.15.0.
How can an anonymous remote attacker exploit CVE-2021-39122?
An anonymous remote attacker can exploit CVE-2021-39122 by making requests to the /rest/api/2/search endpoint to view users' emails.
Is there a fix available for CVE-2021-39122?
Yes, the fix for CVE-2021-39122 is to upgrade to a version of Atlassian Jira Server or Data Center that is not affected by the vulnerability.