CVE Vulnerabilities

CVE-2019-20404

Published: Feb 06, 2020 | Modified: Mar 30, 2022
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.

Affected Software

Name Vendor Start Version End Version
Jira_data_center Atlassian 8.2.4 (including) 8.6.0 (excluding)
Jira_data_center Atlassian 8.6.1 (including) 8.7.0 (excluding)
Jira_server Atlassian 8.2.4 (including) 8.6.0 (excluding)
Jira_server Atlassian 8.6.1 (including) 8.7.0 (excluding)

References