Uploaded image for project: 'Jira Server and Data Center'
  1. Jira Server and Data Center
  2. JRASERVER-72737

Issue watchers continue receiving updates even after their Jira account is revoked - CVE-2021-39119

    XMLWordPrintable

    Details

    • CVSS Score:
      3.1
    • CVSS Severity:
      Low
    • CVE ID:
      CVE-2021-39119

      Description

      Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature.

      The affected versions are before version 8.19.0.

      *Affected versions:*

      • version < 8.19.0

      *Fixed versions:*

      • 8.19.0

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              Unassigned Unassigned
              Reporter:
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: