PT-2021-23259 · Atlassian · Jira

Published

2021-10-26

·

Updated

2024-10-09

·

CVE-2021-41305

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Atlassian Jira Server and Data Center versions prior to 8.13.12
Description The issue allows anonymous remote attackers to view the names of private projects and filters via an Insecure Direct Object References (IDOR) vulnerability in the Average Number of Times in Status Gadget.
Recommendations For versions prior to 8.13.12, update to version 8.13.12 or later to resolve the issue.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2021-41305

Affected Products

Jira