← Back

CVE-2021-39112

nvd nist
Published: Aug 25, 2021Modified: Nov 21, 2024

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: NVD

Description

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature. The affected versions are before version 8.5.15, from version 8.6.0 before 8.13.7, from version 8.14.0 before 8.17.1, and from version 8.18.0 before 8.18.1.

Affected (8)

4 products
Data Center
Jira
Jira Data Center
Jira Server
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Before 8.5.15
Before 8.5.15
Atlassian
From 8.14.0 to 8.17.1
From 8.18.0 to 8.18.1
From 8.6.0 to 8.13.7
Atlassian
From 8.14.0 to 8.17.1
From 8.18.0 to 8.18.1
From 8.6.0 to 8.13.7

References (2)

Source: security@atlassian.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.