Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint. The affected versions are before version 8.21.0.
| Software | From | Fixed in |
|---|---|---|
| atlassian / jira_server | - | 8.13.18 |
| atlassian / jira_server | 8.20.0 | 8.20.6 |
| atlassian / jira_data_center | 8.20.0 | 8.20.6 |
| atlassian / jira_data_center | - | 8.13.18 |