CVE-2021-37843
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no other authentication is provided). The fixed versions are for Jira: 3.6.6.1, 4.0.12, 5.0.5; for Confluence 3.6.6, 4.0.12, 5.0.5; for Bitbucket 2.5.9, 3.6.6, 4.0.12, 5.0.5; for Bamboo 2.5.9, 3.6.6, 4.0.12, 5.0.5; and for Fisheye 2.5.9.
Las aplicaciones SAML SSO de resolución para los productos de Atlassian permiten a un atacante remoto acceder a una cuenta de usuario cuando sólo se conoce el nombre de usuario (es decir, no se proporciona ninguna otra autenticación). Las versiones corregidas son para Jira: 3.6.6.1, 4.0.12, 5.0.5; para Confluence 3.6.6, 4.0.12, 5.0.5; para Bitbucket 2.5.9, 3.6.6, 4.0.12, 5.0.5; para Bamboo 2.5.9, 3.6.6, 4.0.12, 5.0.5; y para Fisheye 2.5.9
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-08-02 CVE Reserved
- 2021-08-02 CVE Published
- 2024-04-17 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | < 2.5.9 Search vendor "Atlassian" for product "Saml Single Sign On" and version " < 2.5.9" | bamboo |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | < 2.5.9 Search vendor "Atlassian" for product "Saml Single Sign On" and version " < 2.5.9" | bitbucket |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | < 2.5.9 Search vendor "Atlassian" for product "Saml Single Sign On" and version " < 2.5.9" | fisheye |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | < 3.5.6 Search vendor "Atlassian" for product "Saml Single Sign On" and version " < 3.5.6" | confluence |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | < 3.6.6.1 Search vendor "Atlassian" for product "Saml Single Sign On" and version " < 3.6.6.1" | jira |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | >= 3.0.0 < 3.6.6 Search vendor "Atlassian" for product "Saml Single Sign On" and version " >= 3.0.0 < 3.6.6" | bamboo |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | >= 3.0.0 < 3.6.6 Search vendor "Atlassian" for product "Saml Single Sign On" and version " >= 3.0.0 < 3.6.6" | bitbucket |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | >= 3.6.0 < 3.6.6.1 Search vendor "Atlassian" for product "Saml Single Sign On" and version " >= 3.6.0 < 3.6.6.1" | confluence |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | >= 4.0.0 < 4.0.12 Search vendor "Atlassian" for product "Saml Single Sign On" and version " >= 4.0.0 < 4.0.12" | bamboo |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | >= 4.0.0 < 4.0.12 Search vendor "Atlassian" for product "Saml Single Sign On" and version " >= 4.0.0 < 4.0.12" | bitbucket |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | >= 4.0.0 < 4.0.12 Search vendor "Atlassian" for product "Saml Single Sign On" and version " >= 4.0.0 < 4.0.12" | confluence |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | >= 4.0.0 < 4.0.12 Search vendor "Atlassian" for product "Saml Single Sign On" and version " >= 4.0.0 < 4.0.12" | jira |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | >= 5.0.0 < 5.0.5 Search vendor "Atlassian" for product "Saml Single Sign On" and version " >= 5.0.0 < 5.0.5" | bamboo |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | >= 5.0.0 < 5.0.5 Search vendor "Atlassian" for product "Saml Single Sign On" and version " >= 5.0.0 < 5.0.5" | bitbucket |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | >= 5.0.0 < 5.0.5 Search vendor "Atlassian" for product "Saml Single Sign On" and version " >= 5.0.0 < 5.0.5" | confluence |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Saml Single Sign On Search vendor "Atlassian" for product "Saml Single Sign On" | >= 5.0.0 < 5.0.5 Search vendor "Atlassian" for product "Saml Single Sign On" and version " >= 5.0.0 < 5.0.5" | jira |
Affected
|