First published: Wed Nov 03 2021(Updated: )
Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint. The affected versions are before version 8.19.1.
Credit: security@atlassian.com security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Data Center | <8.19.1 | |
Atlassian JIRA | <8.19.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41312 is a vulnerability found in Atlassian Jira Server and Data Center.
The severity of CVE-2021-41312 is high with a CVSS base score of 7.5.
CVE-2021-41312 allows a remote attacker to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint.
Versions up to exclusive 8.19.1 of Atlassian Jira Server and Data Center are affected by CVE-2021-41312.
To fix CVE-2021-41312, upgrade your Atlassian Jira Server or Data Center installation to a version beyond 8.19.1.