4.3
CVE-2021-43951
- EPSS 0.81%
- Veröffentlicht 10.01.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:30:04
- Erkennungen
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information Disclosure vulnerability in the Create Object type mapping feature. The affected versions are before version 4.21.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Atlassian ≫ Jira Service Management SwEdition data_center Version < 4.21.0
Atlassian ≫ Jira Service Management SwEdition server Version < 4.21.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.81% | 0.52 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://jira.atlassian.com/browse/JSDSERVER-10984