CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. It may be remotely exploitable.
CVE
CVE-2021-39127
Severity
MEDIUM
CVSS
5.3
EPSS
1.27%
Original NVD Description
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint via a Broken Access Control vulnerability (BAC) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.
Related CVEs
Other vulnerabilities affecting the same vendor(s)