CVE-2021-37843

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
02/08/2021
Last modified:
11/08/2021

Description

The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no other authentication is provided). The fixed versions are for Jira: 3.6.6.1, 4.0.12, 5.0.5; for Confluence 3.6.6, 4.0.12, 5.0.5; for Bitbucket 2.5.9, 3.6.6, 4.0.12, 5.0.5; for Bamboo 2.5.9, 3.6.6, 4.0.12, 5.0.5; and for Fisheye 2.5.9.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:bamboo:*:* 2.5.9 (excluding)
cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:bitbucket:*:* 2.5.9 (excluding)
cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:fisheye:*:* 2.5.9 (excluding)
cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:confluence:*:* 3.5.6 (excluding)
cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:jira:*:* 3.6.6.1 (excluding)
cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:bamboo:*:* 3.0.0 (including) 3.6.6 (excluding)
cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:bitbucket:*:* 3.0.0 (including) 3.6.6 (excluding)
cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:confluence:*:* 3.6.0 (including) 3.6.6.1 (excluding)
cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:bamboo:*:* 4.0.0 (including) 4.0.12 (excluding)
cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:bitbucket:*:* 4.0.0 (including) 4.0.12 (excluding)
cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:confluence:*:* 4.0.0 (including) 4.0.12 (excluding)
cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:jira:*:* 4.0.0 (including) 4.0.12 (excluding)
cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:bamboo:*:* 5.0.0 (including) 5.0.5 (excluding)
cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:bitbucket:*:* 5.0.0 (including) 5.0.5 (excluding)
cpe:2.3:a:atlassian:saml_single_sign_on:*:*:*:*:*:confluence:*:* 5.0.0 (including) 5.0.5 (excluding)