Description
Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscriptions via a Broken Access Control vulnerability in the /secure/EditSubscription.jspa endpoint. The affected versions are before version 8.13.21, and from version 8.14.0 before 8.20.9.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-30808 | Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscriptions via a Broken Access Control vulnerability in the /secure/EditSubscription.jspa endpoint. The affected versions are before version 8.13.21, and from version 8.14.0 before 8.20.9. |
References
| Link | Providers |
|---|---|
| https://jira.atlassian.com/browse/JRASERVER-73071 |
|
History
Tue, 08 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: atlassian
Published:
Updated: 2024-10-08T14:24:15.786Z
Reserved: 2021-11-16T00:00:00.000Z
Link: CVE-2021-43946
Updated: 2024-08-04T04:10:17.348Z
Status : Modified
Published: 2022-01-05T04:15:07.497
Modified: 2024-11-21T06:30:03.630
Link: CVE-2021-43946
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD