First published: Tue Sep 14 2021(Updated: )
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the /rest/gadget/1.0/createdVsResolved/generate endpoint. The affected versions are before version 8.16.0.
Credit: security@atlassian.com security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Data Center | <8.16.0 | |
Atlassian JIRA | <8.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39123 is a Denial of Service (DoS) vulnerability in Atlassian Jira Server and Data Center before version 8.16.0, which allows unauthenticated remote attackers to impact the application's availability.
The severity of CVE-2021-39123 is high, with a severity value of 7.5.
Versions of Atlassian Jira Server and Data Center before version 8.16.0 are affected by CVE-2021-39123.
An unauthenticated remote attacker can exploit CVE-2021-39123 by sending malicious requests to the /rest/gadget/1.0/createdVsResolved/generate endpoint, causing a Denial of Service (DoS) and impacting the availability of the application.
Yes, the fix for CVE-2021-39123 is to update Atlassian Jira Server and Data Center to version 8.16.0 or higher.