CVE-2021-43948

MEDIUM

Atlassian Jira Service Management Server & Data Center <4.21.0 - In...

Title source: llm
STIX 2.1

Description

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JSDSERVER-10981

Scores

CVSS v3 4.3
EPSS 0.0022
EPSS Percentile 44.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (1)
atlassian/jira_service_management < 4.21.0 (2 CPE variants)
Published Feb 15, 2022
Tracked Since Feb 18, 2026