CVE-2021-43959
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of JSM Insight. When running in an environment like Amazon EC2, this flaw may be used to access to a metadata resource that provides access credentials and other potentially confidential information. The affected versions are before version 4.13.20, from version 4.14.0 before 4.20.8, and from version 4.21.0 before 4.22.2.
Las versiones afectadas de Atlassian Jira Service Management Server y Data Center permiten a atacantes remotos autenticados acceder al contenido de los recursos de la red interna por medio de una vulnerabilidad de tipo Server-Side Request Forgery (SSRF) en la funcionalidad CSV importing de JSM Insight. Cuando se ejecuta en un entorno como Amazon EC2, este fallo puede usarse para acceder a un recurso de metadatos que proporciona credenciales de acceso y otra información potencialmente confidencial. Las versiones afectadas son anteriores a 4.13.20, desde versión 4.14.0 hasta 4.20.8, y desde versión 4.21.0 hasta 4.22.2.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2021-11-16 CVE Reserved
- 2022-07-26 CVE Published
- 2024-10-03 CVE Updated
- 2024-10-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://jira.atlassian.com/browse/JSDSERVER-11898 | 2022-08-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Atlassian Search vendor "Atlassian" | Jira Service Desk Search vendor "Atlassian" for product "Jira Service Desk" | < 4.13.20 Search vendor "Atlassian" for product "Jira Service Desk" and version " < 4.13.20" | data_center |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Jira Service Desk Search vendor "Atlassian" for product "Jira Service Desk" | < 4.13.20 Search vendor "Atlassian" for product "Jira Service Desk" and version " < 4.13.20" | server |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Jira Service Management Search vendor "Atlassian" for product "Jira Service Management" | >= 4.14.0 < 4.20.8 Search vendor "Atlassian" for product "Jira Service Management" and version " >= 4.14.0 < 4.20.8" | data_center |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Jira Service Management Search vendor "Atlassian" for product "Jira Service Management" | >= 4.14.0 < 4.20.8 Search vendor "Atlassian" for product "Jira Service Management" and version " >= 4.14.0 < 4.20.8" | server |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Jira Service Management Search vendor "Atlassian" for product "Jira Service Management" | >= 4.21.0 < 4.22.2 Search vendor "Atlassian" for product "Jira Service Management" and version " >= 4.21.0 < 4.22.2" | data_center |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Jira Service Management Search vendor "Atlassian" for product "Jira Service Management" | >= 4.21.0 < 4.22.2 Search vendor "Atlassian" for product "Jira Service Management" and version " >= 4.21.0 < 4.22.2" | server |
Affected
|