CVE-2021-39126: CSRF
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cross-Site Request Forgery (CSRF) vulnerability, following an Information Disclosure vulnerability in the referrer headers which discloses a user's CSRF token. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Jira Server and Data Center vulnerability?
The vulnerability ID for this Jira Server and Data Center vulnerability is CVE-2021-39126.
What is the severity level of CVE-2021-39126?
CVE-2021-39126 has a severity level of medium (6.5).
How can remote attackers exploit CVE-2021-39126?
Remote attackers can exploit CVE-2021-39126 by using a Cross-Site Request Forgery (CSRF) vulnerability and an Information Disclosure vulnerability in the referrer headers to modify various resources.
Which versions of Atlassian Jira Server are affected by CVE-2021-39126?
Versions up to 8.5.10 and versions between 8.6.0 and 8.13.1 of Atlassian Jira Server are affected by CVE-2021-39126.
Which versions of Atlassian Jira Data Center are affected by CVE-2021-39126?
Versions up to 8.5.10 and versions between 8.6.0 and 8.13.1 of Atlassian Jira Data Center are affected by CVE-2021-39126.
Is there a known fix for CVE-2021-39126?
Yes, a fix is available for CVE-2021-39126. Please refer to the official reference for more information.