QID 730035
Date Published: 2021-04-06
QID 730035: Atlassian Jira Server Information Disclosure Vulnerability(JRASERVER-72272)
Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
Affected version:
Atlassian Jira Server and Data Center version prior to 8.5.13
Atlassian Jira Server and Data Center version from 8.6.0 and prior to 8.13.5
Atlassian Jira Server and Data Center version from 8.14.0 and prior to 8.15.1
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Allows remote anonymous attackers to determine if a group exists and members of groups if they are assigned to publicly visible issue field.
Solution
Customers are advised to refer to JRASERVER-72272 for updates pertaining to this vulnerability.
Vendor References
- JRASERVER-72272 -
jira.atlassian.com/browse/JRASERVER-72272
CVEs related to QID 730035
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72272 |
|