CVE-2021-39112
No sign of exploitation. No public exploitation artifact known so far.
Atlassian Jira's Project Shortcuts feature has a vulnerability that allows attackers to trick users into visiting malicious websites through a technique called reverse tabnapping. This happens because the application doesn't properly secure links when opening them in new browser tabs.
A reverse tabnapping vulnerability in the Project Shortcuts feature allows remote attackers to redirect users to attacker-controlled URLs. The vulnerability exists due to insufficient validation of URL targets and improper use of the 'target' attribute in link generation, enabling an attacker to manipulate the window.opener property and redirect the original tab after the user navigates to a new tab.