-
Public Security Vulnerability
-
Resolution: Fixed
-
Low
-
8.5.0, 8.13.0, 8.15.0
-
None
-
3.5
-
Low
-
CVE-2021-26071
The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability.
Affected versions:
- version < 8.5.13
- 8.6.0 ≤ version < 8.13.5
- 8.14.0 ≤ version < 8.15.1
Fixed versions:
- 8.5.13
- 8.13.5
- 8.15.1
[JRASERVER-72233] CSRF in the SetFeatureEnabled.jspa resource - CVE-2021-26071
CVE ID | New: CVE-2021-26071 |
Labels | Original: CVE-2021-26071 advisory advisory-to-release dont-import security | New: CVE-2021-26071 advisory advisory-released dont-import security |
Security | Original: Reporter and Atlassian Staff [ 10751 ] |
Labels | Original: advisory advisory-to-release dont-import security | New: CVE-2021-26071 advisory advisory-to-release dont-import security |
Summary | Original: CSRF in the SetFeatureEnabled.jspa resource - CVE-2021-XXX | New: CSRF in the SetFeatureEnabled.jspa resource - CVE-2021-26071 |
Description |
Original:
The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability
*Affected versions:* * version < 8.5.13 * 8.6.0 ≤ version < 8.13.5 * 8.14.0 ≤ version < 8.15.1 *Fixed versions:* * 8.5.13 * 8.13.5 * 8.15.1 |
New:
The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability.
*Affected versions:* * version < 8.5.13 * 8.6.0 ≤ version < 8.13.5 * 8.14.0 ≤ version < 8.15.1 *Fixed versions:* * 8.5.13 * 8.13.5 * 8.15.1 |
Security | New: Reporter and Atlassian Staff [ 10751 ] |
Security | Original: Atlassian Staff [ 10750 ] |
Description | Original: The |
New:
The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability
*Affected versions:* * version < 8.5.13 * 8.6.0 ≤ version < 8.13.5 * 8.14.0 ≤ version < 8.15.1 *Fixed versions:* * 8.5.13 * 8.13.5 * 8.15.1 |
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 3.5 => Low severity
Exploitability Metrics
Scope Metric
Impact Metrics
https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N