First published: Tue Feb 15 2022(Updated: )
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Jira Service Management | <4.21.0 | |
Atlassian Jira Service Management | <4.21.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-43948.
The severity of CVE-2021-43948 is medium with a severity value of 4.3.
Affected versions of Atlassian Jira Service Management Server and Data Center are versions before version 4.21.0.
Authenticated remote attackers can exploit CVE-2021-43948 to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature.
You can find more information about CVE-2021-43948 at the following link: [CVE-2021-43948](https://jira.atlassian.com/browse/JSDSERVER-10981).