CVE-2021-43948

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:*

History

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-863 NVD-CWE-Other

04 Mar 2022, 15:29

Type Values Removed Values Added
First Time Atlassian jira Service Management
CPE cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:data_center:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*
cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:*

23 Feb 2022, 02:37

Type Values Removed Values Added
CPE cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:data_center:*:*:*:*:*:*:*:*
References (MISC) https://jira.atlassian.com/browse/JSDSERVER-10981 - (MISC) https://jira.atlassian.com/browse/JSDSERVER-10981 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.3
CWE CWE-863
First Time Atlassian data Center
Atlassian jira
Atlassian

15 Feb 2022, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-02-15 04:15

Updated : 2023-12-10 14:22


NVD link : CVE-2021-43948

Mitre link : CVE-2021-43948

CVE.ORG link : CVE-2021-43948


JSON object : View

Products Affected

atlassian

  • jira_service_management