Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2024-21685

Disclosure Date: June 18, 2024
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center.

This Information Disclosure vulnerability, with a CVSS Score of 7.4, allows an unauthenticated attacker to view sensitive information via an Information Disclosure vulnerability which has high impact to confidentiality, no impact to integrity, no impact to availability, and requires user interaction. 

Atlassian recommends that Jira Core Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:

	Jira Core Data Center 9.4: Upgrade to a release greater than or equal to 9.4.21

	Jira Core Data Center 9.12: Upgrade to a release greater than or equal to 9.12.8

	Jira Core Data Center 9.16: Upgrade to a release greater than or equal to 9.16.0



See the release notes. You can download the latest version of Jira Core Data Center from the download center. 

This vulnerability was found internally.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Vector:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown

General Information

Vendors

  • Atlassian

Products

  • Jira Core Data Center

Additional Info

Technical Analysis