CVE Vulnerabilities

CVE-2019-20404

Published: Feb 06, 2020 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.

Affected Software

NameVendorStart VersionEnd Version
Jira_data_centerAtlassian8.2.4 (including)8.6.0 (excluding)
Jira_data_centerAtlassian8.6.1 (including)8.7.0 (excluding)
Jira_serverAtlassian8.2.4 (including)8.6.0 (excluding)
Jira_serverAtlassian8.6.1 (including)8.7.0 (excluding)

References