CVE Published: 15/02/2022 |
CVE Updated: 08/10/2024 |
CVE Year: 2021 Source: atlassian |
Vendor: Atlassian |
Product: Jira Server Status : PUBLISHED
CVE-2021-43953 Description
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The affected versions are before version 8.13.16, and from version 8.14.0 before 8.20.5.