Unrated severityNVD Advisory· Published Dec 8, 2021· Updated Oct 10, 2024
CVE-2021-41309
CVE-2021-41309
Description
Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs of another user's Jira Service Management project via a Broken Authentication vulnerability in the /plugins/servlet/audit/resource endpoint. The affected versions of Jira Server and Data Center are before version 8.19.1.
Affected products
2- Range: unspecified
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- jira.atlassian.com/browse/JRASERVER-72803mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.