VYPR
Critical severity9.8NVD Advisory· Published Aug 2, 2021· Updated Jun 17, 2026

CVE-2021-37843

CVE-2021-37843

Description

The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no other authentication is provided). The fixed versions are for Jira: 3.6.6.1, 4.0.12, 5.0.5; for Confluence 3.6.6, 4.0.12, 5.0.5; for Bitbucket 2.5.9, 3.6.6, 4.0.12, 5.0.5; for Bamboo 2.5.9, 3.6.6, 4.0.12, 5.0.5; and for Fisheye 2.5.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

12
  • cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:bamboo:*:*+ 4 more
    • cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:bamboo:*:*range: <2.5.9
    • cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:bitbucket:*:*range: <2.5.9
    • cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:confluence:*:*range: <3.5.6
    • cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:fisheye:*:*range: <2.5.9
    • cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:jira:*:*range: <3.6.6.1
  • Atlassian/Jira, Confluence, Bitbucket, Bamboo, Fisheyedescription
  • Range: unknown
  • Range: 2.5.9
  • Atlassian/Bamboollm-fuzzy
    Range: 2.5.9, 3.6.6, 4.0.12, 5.0.5
  • Range: 3.6.6, 4.0.12, 5.0.5
  • Atlassian/Jirallm-fuzzy
    Range: 3.6.6.1, 4.0.12, 5.0.5
  • Range: 2.5.9, 3.6.6, 4.0.12, 5.0.5

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.