← Vulnerability feed

Vulnerability record · CVE-2021-41311 · published 8 December 2021

CVE-2021-41311: Atlassian jira software data center improper authentication vulnerability

Atlassian · Jira Software Data Center

Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint. The affected versions are before version 8.19.1.

7.5 CVSS 3.1 High EPSS 0.84% · top 43.9% CWE-287 · Improper authentication
7.5CVSS 3.1 base score, v2 5.0
0.84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint. The affected versions are before version 8.19.1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41311 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-14172Atlassian jira deserialization of untrusted data vulnerabilityThis issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. Th…EPSS 2.5%9.8CVE-2019-20409Atlassian jira injection vulnerabilityThe way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote…EPSS 2.5%7.5CVE-2021-41305Atlassian jira insecure direct object reference vulnerabilityAffected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an …EPSS 1.2%7.5CVE-2021-41306Atlassian jira insecure direct object reference vulnerabilityAffected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure …EPSS 1.6%7.5CVE-2021-41307Atlassian jira insecure direct object reference vulnerabilityAffected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private f…EPSS 1.7%7.5CVE-2020-14178Atlassian jira vulnerabilityAffected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerabili…EPSS 3.1%7.5CVE-2019-20898Atlassian jira vulnerabilityAffected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the …EPSS 1.3%7.5CVE-2020-14167Atlassian jira vulnerabilityThe MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, and from 8…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2021-41311), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.