Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-72233

CSRF in the SetFeatureEnabled.jspa resource - CVE-2021-26071

    • 3.5
    • Low
    • CVE-2021-26071

      The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability.

       

      Affected versions:

      • version < 8.5.13
      • 8.6.0 ≤ version < 8.13.5
      • 8.14.0 ≤ version < 8.15.1

      Fixed versions:

      • 8.5.13
      • 8.13.5
      • 8.15.1  

            [JRASERVER-72233] CSRF in the SetFeatureEnabled.jspa resource - CVE-2021-26071

            Security Metrics Bot made changes -
            CVE ID New: CVE-2021-26071
            David Black made changes -
            Labels Original: CVE-2021-26071 advisory advisory-to-release dont-import security New: CVE-2021-26071 advisory advisory-released dont-import security
            David Black made changes -
            Security Original: Reporter and Atlassian Staff [ 10751 ]

            This is an independent assessment and you should evaluate its applicability to your own IT environment.

            CVSS v3 score: 3.5 => Low severity

            Exploitability Metrics

            Attack Vector Network
            Attack Complexity Low
            Privileges Required Low
            User Interaction Required

            Scope Metric

            Scope Unchanged

            Impact Metrics

            Confidentiality Low
            Integrity None
            Availability None

            https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

            David Black added a comment - This is an independent assessment and you should evaluate its applicability to your own IT environment. CVSS v3 score: 3.5 => Low severity Exploitability Metrics Attack Vector Network Attack Complexity Low Privileges Required Low User Interaction Required Scope Metric Scope Unchanged Impact Metrics Confidentiality Low Integrity None Availability None https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
            David Black made changes -
            Labels Original: advisory advisory-to-release dont-import security New: CVE-2021-26071 advisory advisory-to-release dont-import security
            David Black made changes -
            Summary Original: CSRF in the SetFeatureEnabled.jspa resource - CVE-2021-XXX New: CSRF in the SetFeatureEnabled.jspa resource - CVE-2021-26071
            David Black made changes -
            Description Original: The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability


             

            *Affected versions:*
             * version < 8.5.13
             * 8.6.0 ≤ version < 8.13.5
             * 8.14.0 ≤ version < 8.15.1

            *Fixed versions:*
             * 8.5.13
             * 8.13.5
             * 8.15.1  
            New: The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability.


             

            *Affected versions:*
             * version < 8.5.13
             * 8.6.0 ≤ version < 8.13.5
             * 8.14.0 ≤ version < 8.15.1

            *Fixed versions:*
             * 8.5.13
             * 8.13.5
             * 8.15.1  
            David Black made changes -
            Security New: Reporter and Atlassian Staff [ 10751 ]
            David Black made changes -
            Security Original: Atlassian Staff [ 10750 ]
            David Black made changes -
            Description Original: The New: The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability


             

            *Affected versions:*
             * version < 8.5.13
             * 8.6.0 ≤ version < 8.13.5
             * 8.14.0 ≤ version < 8.15.1

            *Fixed versions:*
             * 8.5.13
             * 8.13.5
             * 8.15.1  

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: