QID 150365
Date Published: 2021-09-29
QID 150365: Atlassian Jira Server - Mobile site reveals the summary titles of privately linked tickets (CVE-2020-36235)
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
The installed version of Jira Atlassian Server allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view.
Affected versions:
Before version 8.13.2
From version 8.14.0 before 8.14.1
Successful exploitation would lead to Information Disclosure vulnerability in the mobile site view, which can help the attacker carry out further attacks and obtain sensitive information.
Solution
Upgrade the Atlassian Jira to new version.
Vendor References
- JRASERVER-71950 -
jira.atlassian.com/browse/JRASERVER-71950
CVEs related to QID 150365
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-71950 |
|