SB2021110419 - Improper authorization in Atlassian Jira
Published: November 4, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authorization (CVE-ID: CVE-2021-41312)
The vulnerability allows a remote user to bypass authorization process.
The vulnerability exists due to an error in when processing requests in the /secure/ViewCollectors endpoint. A remote user with revoked access from the Jira Service Management can enable and disable Issue Collectors on Jira Service Management projects.
Remediation
Install update from vendor's website.