CVE-2020-36289
Summary
| CVE | CVE-2020-36289 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-12 04:15:00 UTC |
| Updated | 2022-06-28 14:11:00 UTC |
| Description | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730086 Atlassian Jira Server Information Disclosure Vulnerability (JRASERVER-71559)