CVE-2021-43949: Infoleak
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view private objects via a Broken Access Control vulnerability in the Custom Fields feature. The affected versions are before version 4.21.0.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-43949?
CVE-2021-43949 is a vulnerability in Atlassian Jira Service Management Server and Data Center that allows authenticated remote attackers to view private objects.
How can an attacker exploit CVE-2021-43949?
An attacker can exploit CVE-2021-43949 by using a Broken Access Control vulnerability in the Custom Fields feature of Atlassian Jira Service Management to view private objects.
What is the severity of CVE-2021-43949?
The severity of CVE-2021-43949 is medium with a CVSS score of 4.3.
Which versions of Atlassian Jira Service Management are affected by CVE-2021-43949?
Versions of Atlassian Jira Service Management before 4.21.0 are affected by CVE-2021-43949.
How do I fix CVE-2021-43949?
To fix CVE-2021-43949, update Atlassian Jira Service Management to version 4.21.0 or later.