Description
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view users' emails via an Information Disclosure vulnerability in the /rest/api/2/search endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-25558 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view users' emails via an Information Disclosure vulnerability in the /rest/api/2/search endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1. |
References
| Link | Providers |
|---|---|
| https://jira.atlassian.com/browse/JRASERVER-72293 |
|
History
Thu, 10 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: atlassian
Published:
Updated: 2024-10-10T15:17:51.221Z
Reserved: 2021-08-16T00:00:00.000Z
Link: CVE-2021-39122
Updated: 2024-08-04T01:58:17.788Z
Status : Modified
Published: 2021-09-08T02:15:06.787
Modified: 2024-11-21T06:18:37.557
Link: CVE-2021-39122
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD