QID 150370
Date Published: 2021-10-12
QID 150370: Atlassian Jira Server - Custom field options are exposed via an unauthenticated REST API endpoint - (CVE-2020-36237)
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
The installed version of Jira Atlassian Server allow unauthenticated remote attackers to view custom field options via an Information Disclosure vulnerability in the /rest/api/2/customFieldOption/ endpoint.
Affected versions:
before version 8.15.0
Successful exploitation would lead attackers to enumerate custom fields, which can help the attacker carry out further attacks and obtain sensitive information.
Solution
Upgrade the Atlassian Jira to new version.
Vendor References
- JRASERVER-72064 -
jira.atlassian.com/browse/JRASERVER-72064
CVEs related to QID 150370
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72064 |
|