CVE-2021-39125: Medium severity Atlassian Data Center vulnerability
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to discover the usernames of users via an enumeration vulnerability in the password reset page. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.5.10 - Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.13.1
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-39125.
What is the severity of CVE-2021-39125?
The severity of CVE-2021-39125 is medium (5.3).
How does CVE-2021-39125 affect Atlassian Jira Server and Data Center?
CVE-2021-39125 allows anonymous remote attackers to discover the usernames of users through an enumeration vulnerability on the password reset page in affected versions of Atlassian Jira Server and Data Center.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2021-39125?
The affected versions of Atlassian Jira Server and Data Center are before version 8.5.10, and from version 8.6.0 before 8.13.1.
Is there a fix available for CVE-2021-39125?
Yes, upgrading to version 8.5.10 or higher, or version 8.13.1 or higher, will fix CVE-2021-39125.