CVE-2021-43948

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:*

History

21 Nov 2024, 06:30

Type Values Removed Values Added
References () https://jira.atlassian.com/browse/JSDSERVER-10981 - Vendor Advisory () https://jira.atlassian.com/browse/JSDSERVER-10981 - Vendor Advisory

Information

Published : 2022-02-15 04:15

Updated : 2024-11-21 06:30


NVD link : CVE-2021-43948

Mitre link : CVE-2021-43948

CVE.ORG link : CVE-2021-43948


JSON object : View

Products Affected

atlassian

  • jira_service_management