Lucene search

K
atlassianSecurity-metrics-botJSDSERVER-10981
HistoryDec 22, 2021 - 3:12 a.m.

Names of private objects are leaked to unauthorized users via the "Move objects" feature - CVE-2021-43948

2021-12-2203:12:49
security-metrics-bot
jira.atlassian.com
35
atlassian jira service management
improper authorization
remote attackers
version 4.21.0
data center

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

35.3%

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the “Move objects” feature.

The affected versions are before version 4.21.0.

Affected versions:

  • version < 4.21.0

Fixed versions:

  • 4.21.0

Affected configurations

Vulners
Node
atlassianjira_service_managementRange4.20.0data_center
OR
atlassianjira_service_managementRange<4.21.0data_center
OR
atlassianjira_service_managementRange<4.20.2data_center
VendorProductVersionCPE
atlassianjira_service_management*cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

35.3%

Related for JSDSERVER-10981