CVE-2021-43959
Published on: Not Yet Published
Last Modified on: 08/02/2022 02:02:00 PM UTC
Certain versions of Jira Service Desk from Atlassian contain the following vulnerability:
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of JSM Insight. When running in an environment like Amazon EC2, this flaw may be used to access to a metadata resource that provides access credentials and other potentially confidential information. The affected versions are before version 4.13.20, from version 4.14.0 before 4.20.8, and from version 4.21.0 before 4.22.2.
- CVE-2021-43959 has been assigned by
securit[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 5.7 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Log in with Atlassian account | jira.atlassian.com text/html |
![]() |
Related QID Numbers
- 730576 Atlassian Jira Service Management Server and Data Center CSV Import Vulnerability (JSDSERVER-11898)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Atlassian | Jira Service Desk | All | All | All | All |
Application | Atlassian | Jira Service Desk | All | All | All | All |
Application | Atlassian | Jira Service Management | All | All | All | All |
Application | Atlassian | Jira Service Management | All | All | All | All |
- cpe:2.3:a:atlassian:jira_service_desk:*:*:*:*:data_center:*:*:*:
- cpe:2.3:a:atlassian:jira_service_desk:*:*:*:*:server:*:*:*:
- cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*:
- cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:server:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-43959 : Affected versions of #Atlassian #Jira Service Management Server and Data Center allow authenticate… twitter.com/i/web/status/1… | 2022-07-26 08:03:33 |
![]() |
CVE-2021-43959 | 2022-07-26 09:38:47 |