VulnerabilityModified
CVE-2021-43948
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature.
MEDIUM 4.3EPSS 0.84%
Does this matter?
Lower severity and a low EPSS score (0.84%). Track it; it rarely justifies an emergency change on its own.
Description
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.84% probability · 56th percentile
- CISA KEV
- Not listed
- Affected
- atlassian/jira service management
- Source
- security@atlassian.com
References
- https://jira.atlassian.com/browse/JSDSERVER-10981Vendor Advisory
- https://jira.atlassian.com/browse/JSDSERVER-10981Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.