CVE-2021-41312: High severity atlassian data center vulnerability
Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint. The affected versions are before version 8.19.1.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-41312?
CVE-2021-41312 is a vulnerability found in Atlassian Jira Server and Data Center.
What is the severity of CVE-2021-41312?
The severity of CVE-2021-41312 is high with a CVSS base score of 7.5.
How does CVE-2021-41312 affect Atlassian Jira?
CVE-2021-41312 allows a remote attacker to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2021-41312?
Versions up to exclusive 8.19.1 of Atlassian Jira Server and Data Center are affected by CVE-2021-41312.
How can I fix CVE-2021-41312?
To fix CVE-2021-41312, upgrade your Atlassian Jira Server or Data Center installation to a version beyond 8.19.1.