{
   "CVE_data_meta": {
      "ASSIGNER": "security@atlassian.com", 
      "DATE_PUBLIC": "2021-08-18T00:00:00",
      "ID": "CVE-2021-39121", 
      "STATE": "PUBLIC"
   }, 
   "affects": {
      "vendor": {
         "vendor_data": [
            {
               "product": {
                  "product_data": [
                     {
                        "product_name": "Jira Server",
                        "version": {
                           "version_data": [
                              {
                                 "version_value": "8.5.18",
                                 "version_affected": "<"
                              },
                              {
                                 "version_value": "8.6.0",
                                 "version_affected": ">="
                              }, 
                              {
                                 "version_value": "8.13.10",
                                 "version_affected": "<"
                              },
                              {
                                 "version_value": "8.14.0",
                                 "version_affected": ">="
                              },
                              {
                                 "version_value": "8.18.2",
                                 "version_affected": "<"
                              }
                           ]
                        }
                            },
                            {
                        "product_name": "Jira Data Center",
                        "version": {
                           "version_data": [
                              {
                                 "version_value": "8.5.18",
                                 "version_affected": "<"
                              },
                              {
                                 "version_value": "8.6.0",
                                 "version_affected": ">="
                              },
                              {
                                 "version_value": "8.13.10",
                                 "version_affected": "<"
                              },
                              {
                                 "version_value": "8.14.0",
                                 "version_affected": ">="
                              },
                              {
                                 "version_value": "8.18.2",
                                 "version_affected": "<"
                              }
                           ]
                        }
                     }
                  ]
               }, 
               "vendor_name": "Atlassian"
            }
         ]
      }
   }, 
   "data_format": "MITRE", 
   "data_type": "CVE", 
   "data_version": "4.0", 
   "description": {
      "description_data": [
         {
            "lang": "eng", 
            "value": "Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projects via an Information Disclosure vulnerability in the /rest/api/latest/projectvalidate/key endpoint. The affected versions are before version 8.5.18, from version 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2."
         }
      ]
   }, 
   "problemtype": {
      "problemtype_data": [
         {
            "description": [
               {
                  "lang": "eng", 
                  "value": "Information Disclosure"
               }
            ]
         }
      ]
   }, 
   "references": {
      "reference_data": [
         {
                "url": "https://jira.atlassian.com/browse/JRASERVER-72715",
                "refsource": "MISC",
                "name": "https://jira.atlassian.com/browse/JRASERVER-72715"
         }
      ]
   }
}