CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-21685: This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. This...

7.4 CVSS

Description

This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center.

This Information Disclosure vulnerability, with a CVSS Score of 7.4, allows an unauthenticated attacker to view sensitive information via an Information Disclosure vulnerability which has high impact to confidentiality, no impact to integrity, no impact to availability, and requires user interaction.

Atlassian recommends that Jira Core Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:

Jira Core Data Center 9.4: Upgrade to a release greater than or equal to 9.4.21

Jira Core Data Center 9.12: Upgrade to a release greater than or equal to 9.12.8

Jira Core Data Center 9.16: Upgrade to a release greater than or equal to 9.16.0



See the release notes. You can download the latest version of Jira Core Data Center from the download center.

This vulnerability was found internally.

Classification

CVE ID: CVE-2024-21685

CVSS Base Severity: HIGH

CVSS Base Score: 7.4

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

Problem Types

Information Disclosure

Affected Products

Vendor: Atlassian

Product: Jira Core Data Center

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.21% (probability of being exploited)

EPSS Percentile: 43.41% (scored less or equal to compared to others)

EPSS Date: 2025-04-15 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: total

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-21685
https://confluence.atlassian.com/pages/viewpage.action?pageId=1409286211
https://jira.atlassian.com/browse/JRASERVER-77713

Timeline