First published: Tue Feb 15 2022(Updated: )
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature. The affected versions are before version 4.21.0.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Jira Service Management | <4.21.0 | |
Atlassian Jira Service Management | <4.21.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43950 is a vulnerability in Atlassian Jira Service Management Server and Data Center that allows authenticated remote attackers to view import source configuration information.
CVE-2021-43950 affects versions of Atlassian Jira Service Management Server and Data Center before version 4.21.0.
The severity of CVE-2021-43950 is medium with a severity value of 4.3.
Authenticated remote attackers can exploit CVE-2021-43950 to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature.
To fix CVE-2021-43950, update Atlassian Jira Service Management Server and Data Center to version 4.21.0 or later.