CVE Published: 21/10/2021 |
CVE Updated: 10/10/2024 |
CVE Year: 2021 Source: atlassian |
Vendor: Atlassian |
Product: Jira Server Status : PUBLISHED
CVE-2021-39127 Description
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint via a Broken Access Control vulnerability (BAC) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.