CVE-2021-41311

HIGH

Atlassian Jira Server and Data Center < 8.19.1 - Broken Authentication in Project Roles Endpoint

Title source: llm
STIX 2.1

Description

Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint. The affected versions are before version 8.19.1.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-72802

Scores

CVSS v3 7.5
EPSS 0.0019
EPSS Percentile 40.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (1)
atlassian/jira_software_data_center < 8.19.1
Published Dec 08, 2021
Tracked Since Feb 18, 2026