← back
CVE-2021-41308

CVE-2021-41308

EPSS 1.0%CWE-285
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.0%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
26 Oct 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Replication settings via a Broken Access Control vulnerability in the `ReplicationSettings!default.jspa` endpoint. The affected versions are before version 8.6.0, from version 8.7.0 before 8.13.12, and from version 8.14.0 before 8.20.1.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →