CVE-2021-41306: High severity atlassian jira vulnerability
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure Direct Object References (IDOR) vulnerability in the Average Time in Status Gadget. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.0.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-41306.
What is the severity level of CVE-2021-41306?
The severity level of CVE-2021-41306 is high with a score of 7.5.
Which software versions are affected by CVE-2021-41306?
Affected versions of Atlassian Jira Server and Data Center are versions before 8.13.12 and from version 8.14.0 to 8.20.0.
What is the vulnerability type of CVE-2021-41306?
CVE-2021-41306 is an Insecure Direct Object References (IDOR) vulnerability.
How can anonymous remote attackers exploit CVE-2021-41306?
Anonymous remote attackers can exploit CVE-2021-41306 to view private project and filter names via the Average Time in Status Gadget.