CVE-2019-20404
Summary
| CVE | CVE-2019-20404 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-06 03:15:00 UTC |
| Updated | 2022-03-30 13:21:00 UTC |
| Description | The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Atlassian | Jira | All | All | All | All |
| Application | Atlassian | Jira | All | All | All | All |
| Application | Atlassian | Jira Data Center | All | All | All | All |
| Application | Atlassian | Jira Server | All | All | All | All |
| Application | Atlassian | Jira Software Data Center | All | All | All | All |
| Application | Atlassian | Jira Software Data Center | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [JRASERVER-70569] Improper authorization on project titles vulnerability in Jira - CVE-2019-20404 - Create and track feature requests for Atlassian products. | N/A | jira.atlassian.com | Issue Tracking, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.