First published: Mon Jan 10 2022(Updated: )
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information Disclosure vulnerability in the Create Object type mapping feature. The affected versions are before version 4.21.0.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Jira Service Management | <4.21.0 | |
Atlassian Jira Service Management | <4.21.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-43951.
The title of the vulnerability is 'Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information Disclosure vulnerability in the Create Object type mapping feature.'
Versions before 4.21.0 of Atlassian Jira Service Management Server and Data Center are affected.
The severity of CVE-2021-43951 is medium with a severity value of 4.3.
To fix CVE-2021-43951, you need to update your Atlassian Jira Service Management Server or Data Center to version 4.21.0 or newer.