QSearchQSearch

CVE-2021-39123

7.5 HIGH

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to impact the application's availabilit...

Published: 2021-09-14 · Last updated: 2026-06-17

Severity and scoring

CVSS
7.5 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

VendorProduct
atlassiandata_center, jira

Description

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the /rest/gadget/1.0/createdVsResolved/generate endpoint. The affected versions are before version 8.16.0.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2021-41312 Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Man... (7.5 HIGH)
  • CVE-2021-41310 Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a ... (6.1 MEDIUM)
  • CVE-2021-41313 Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configu... (4.3 MEDIUM)
  • CVE-2021-41308 Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Re... (6.5 MEDIUM)
  • CVE-2021-41307 Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects a... (7.5 HIGH)