CVE-2021-43949

Publication date

2022-01-10 15:26:24

Family

atlassian

State

PUBLISHED

Description

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view private objects via a Broken Access Control vulnerability in the Custom Fields feature. The affected versions are before version 4.21.0.