CVE-2021-41311: High severity atlassian jira software data center vulnerability
Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint. The affected versions are before version 8.19.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41311?
The severity of CVE-2021-41311 is high with a severity value of 7.5.
How can an attacker exploit CVE-2021-41311?
Attackers with access to an administrator account that has had its access revoked can exploit CVE-2021-41311 by modifying projects' Users & Roles settings.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2021-41311?
Affected versions of Atlassian Jira Server and Data Center include Atlassian Jira Software Data Center up to version 8.19.1.
What is the vulnerability type of CVE-2021-41311?
CVE-2021-41311 is a Broken Authentication vulnerability.
Is there a reference for CVE-2021-41311?
Yes, you can find more information about CVE-2021-41311 at the following link: [JRASERVER-72802](https://jira.atlassian.com/browse/JRASERVER-72802).