CVE-2021-41307: High severity atlassian jira vulnerability
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private filters via an Insecure Direct Object References (IDOR) vulnerability in the Workload Pie Chart Gadget. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.0.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-41307.
What software is affected by this vulnerability?
Atlassian Jira Server and Data Center versions before 8.13.12 and between 8.14.0 to 8.20.0 are affected.
What is the severity of CVE-2021-41307?
The severity of CVE-2021-41307 is high with a CVSS score of 7.5.
What is the impact of this vulnerability?
This vulnerability allows unauthenticated remote attackers to view the names of private projects and private filters.
Is there a fix for this vulnerability?
Yes, upgrading to version 8.13.12 or later for Atlassian Jira Server and Data Center can fix this vulnerability.