Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-41312

Опубликовано: 03 нояб. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint. The affected versions are before version 8.19.1.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:atlassian:data_center:*:*:*:*:*:*:*:*
Версия до 8.19.1 (исключая)
cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:*
Версия до 8.19.1 (исключая)

EPSS

Процентиль: 64%
0.0048
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287
CWE-287

Связанные уязвимости

CVSS3: 7.5
github
около 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint. The affected versions are before version 8.19.1.

EPSS

Процентиль: 64%
0.0048
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287
CWE-287