PT-2024-4436 · Atlassian · Jira+1

Published

2024-05-14

·

Updated

2024-06-20

·

CVE-2024-21685

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jira Core Data Center versions 9.4.0 through 9.15.0 Jira Core Data Center version 9.12.0
Description The issue is related to insufficient protection of internal data in Atlassian Jira Data Center and Jira Server, allowing a remote attacker to gain unauthorized access to protected information. This Information Disclosure issue allows an unauthenticated attacker to view sensitive information, which has a high impact on confidentiality. The vulnerability was found internally and requires user interaction.
Recommendations For Jira Core Data Center 9.4: Upgrade to a release greater than or equal to 9.4.21 For Jira Core Data Center 9.12: Upgrade to a release greater than or equal to 9.12.8 For Jira Core Data Center 9.16: Upgrade to a release greater than or equal to 9.16.0 As a temporary workaround, consider restricting access to sensitive information until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04938
CVE-2024-21685

Affected Products

Jira
Jira Core