CVE-2021-43953: CSRF
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The affected versions are before version 8.13.16, and from version 8.14.0 before 8.20.5.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-43953?
CVE-2021-43953 is a Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira Server and Data Center.
How does CVE-2021-43953 impact Atlassian Jira Server and Data Center?
CVE-2021-43953 allows unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2021-43953?
Affected versions of Atlassian Jira Server and Data Center are before 8.13.16 and between 8.14.0 and 8.20.5.
What is the severity of CVE-2021-43953?
The severity of CVE-2021-43953 is medium (4.3).
How can I fix CVE-2021-43953?
To fix CVE-2021-43953, update Atlassian Jira Server or Data Center to version 8.13.16 or above, or between 8.20.5 and 8.14.0.