CVE-2021-43951

MEDIUM

Atlassian Jira Service Management <4.21.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information Disclosure vulnerability in the Create Object type mapping feature. The affected versions are before version 4.21.0.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JSDSERVER-10984

Scores

CVSS v3 4.3
EPSS 0.0017
EPSS Percentile 37.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
atlassian/jira_service_management < 4.21.0 (2 CPE variants)
Published Jan 10, 2022
Tracked Since Feb 18, 2026