First published: Mon Jan 10 2022(Updated: )
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view private objects via a Broken Access Control vulnerability in the Custom Fields feature. The affected versions are before version 4.21.0.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Jira Service Management | <4.21.0 | |
Atlassian Jira Service Management | <4.21.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43949 is a vulnerability in Atlassian Jira Service Management Server and Data Center that allows authenticated remote attackers to view private objects.
An attacker can exploit CVE-2021-43949 by using a Broken Access Control vulnerability in the Custom Fields feature of Atlassian Jira Service Management to view private objects.
The severity of CVE-2021-43949 is medium with a CVSS score of 4.3.
Versions of Atlassian Jira Service Management before 4.21.0 are affected by CVE-2021-43949.
To fix CVE-2021-43949, update Atlassian Jira Service Management to version 4.21.0 or later.