CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.2. It may be remotely exploitable.
CVE
CVE-2021-26070
Severity
HIGH
CVSS
7.2
EPSS
1.96%
Original NVD Description
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.
Related CVEs
Other vulnerabilities affecting the same vendor(s)