CVE-2021-39123: High severity Atlassian Data Center vulnerability
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the /rest/gadget/1.0/createdVsResolved/generate endpoint. The affected versions are before version 8.16.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.16.0
Event History
Frequently Asked Questions
What is CVE-2021-39123?
CVE-2021-39123 is a Denial of Service (DoS) vulnerability in Atlassian Jira Server and Data Center before version 8.16.0, which allows unauthenticated remote attackers to impact the application's availability.
What is the severity of CVE-2021-39123?
The severity of CVE-2021-39123 is high, with a severity value of 7.5.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2021-39123?
Versions of Atlassian Jira Server and Data Center before version 8.16.0 are affected by CVE-2021-39123.
How can an unauthenticated remote attacker exploit CVE-2021-39123?
An unauthenticated remote attacker can exploit CVE-2021-39123 by sending malicious requests to the /rest/gadget/1.0/createdVsResolved/generate endpoint, causing a Denial of Service (DoS) and impacting the availability of the application.
Is there a fix available for CVE-2021-39123?
Yes, the fix for CVE-2021-39123 is to update Atlassian Jira Server and Data Center to version 8.16.0 or higher.