Uploaded image for project: 'Jira Server and Data Center'
  1. Jira Server and Data Center
  2. JRASERVER-72737

Issue watchers continue receiving updates even after their Jira account is revoked - CVE-2021-39119

    XMLWordPrintable

Details

    • 3.1
    • Low
    • CVE-2021-39119

    Description

      Summary

      Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature.

      The affected versions are before version 8.19.0.

      Affected versions:

      • version < 8.19.0

      Fixed versions:

      • 8.19.0

      Note on fix

      Due to this change, Jira notifications (batched and non-batched) not sent anymore to users who don't have application access after Jira upgrade to 8.19.0, see related KB

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              10 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: