CVE-2021-26071
Summary
| CVE | CVE-2021-26071 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-01 03:15:00 UTC |
| Updated | 2022-03-30 13:29:00 UTC |
| Description | The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [JRASERVER-72233] CSRF in the SetFeatureEnabled.jspa resource - CVE-2021-26071 - Create and track feature requests for Atlassian products. |
MISC |
jira.atlassian.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150514 Atlassian Jira Server Multiple Vulnerabilities (JRASERVER-72252,JRASERVER-72316,JRASERVER-72233,JRASERVER-72010)
- 730104 Atlassian Jira Server Multiple Security Vulnerabilities (JRASERVER-72249, JRASERVER-72233)