CVE-2021-41313: Medium severity atlassian data center vulnerability
Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configurations via an Improper Authorization vulnerability in the /secure/admin/ConfigureBatching!default.jspa endpoint. The affected versions are before version 8.20.7.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-41313.
What versions of Atlassian Jira Server and Data Center are affected?
Versions of Atlassian Jira Server and Data Center before 8.20.7 are affected.
What is the severity of CVE-2021-41313?
The severity of CVE-2021-41313 is medium, with a CVSS score of 4.3.
How can authenticated but non-admin remote attackers exploit this vulnerability?
Authenticated but non-admin remote attackers can exploit this vulnerability by editing email batch configurations via the /secure/admin/ConfigureBatching!default.jspa endpoint.
Is there a fix available for this vulnerability?
Yes, updating Atlassian Jira Server and Data Center to version 8.20.7 or later will fix this vulnerability.