Vulnerability Description
Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint. The affected versions are before version 8.19.1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Jira Software Data Center | < 8.19.1 |
Related Weaknesses (CWE)
References
- https://jira.atlassian.com/browse/JRASERVER-72802Vendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-72802Vendor Advisory
FAQ
What is CVE-2021-41311?
CVE-2021-41311 is a vulnerability with a CVSS score of 7.5 (HIGH). Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Bro...
How severe is CVE-2021-41311?
CVE-2021-41311 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-41311?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Jira Software Data Center.