CVE-2021-39119

MEDIUM

Atlassian Jira Server and Data Center < 8.19.0 - Broken Access Control in Issue Notification Feature

Title source: llm
STIX 2.1

Description

Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature. The affected versions are before version 8.19.0.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-72737

Scores

CVSS v3 5.3
EPSS 0.0019
EPSS Percentile 40.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
atlassian/data_center < 8.19.0
atlassian/jira < 8.19.0
Published Sep 01, 2021
Tracked Since Feb 18, 2026