cbcvebase.
CVE-2021-39124
published 2021-09-14

CVE-2021-39124: The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able…

medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request.

Affected

4 ranges
VendorProductVersion rangeFixed in
atlassiandata_center< 8.16.08.16.0
atlassianjira< 8.16.08.16.0
atlassianjira_data_center>= unspecified < 8.16.08.16.0
atlassianjira_server>= unspecified < 8.16.08.16.0