Security Advisory

CVE-2021-26070

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-03-22 04:40:11
Last updated 2024-09-16 19:42:02
Assigner atlassian
State PUBLISHED

Description

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.