7.5
CVSSv3

CVE-2021-41306

Published: 26/10/2021 Updated: 03/05/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote malicious users to view private project and filter names via an Insecure Direct Object References (IDOR) vulnerability in the Average Time in Status Gadget. The affected versions are before version 8.13.12, and from version 8.14.0 prior to 8.20.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

atlassian jira

atlassian jira software data center

atlassian jira server