CVE-2021-39112

MEDIUM

Atlassian Jira Server/Data Center <8.5.15, <8.6.0-8.13.7, <8.14.0-8...

Title source: llm
STIX 2.1

Description

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature. The affected versions are before version 8.5.15, from version 8.6.0 before 8.13.7, from version 8.14.0 before 8.17.1, and from version 8.18.0 before 8.18.1.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-72433

Scores

CVSS v3 4.8
EPSS 0.0020
EPSS Percentile 41.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601 CWE-1022
Status published
Products (4)
atlassian/data_center < 8.5.15
atlassian/jira < 8.5.15
atlassian/jira_data_center 8.6.0 - 8.13.7
atlassian/jira_server 8.6.0 - 8.13.7
Published Aug 25, 2021
Tracked Since Feb 18, 2026