QID 730086
Date Published: 2021-05-18
QID 730086: Atlassian Jira Server Information Disclosure Vulnerability (JRASERVER-71559)
Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
Affected by below vulnerability:
CVE-2020-36289: Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint.
Affected version:
Atlassian Jira Server version prior to 8.5.13
Atlassian Jira Server from version 8.6.0 prior to 8.13.5
Atlassian Jira Server from version 8.14.0 prior to 8.15.1
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability.
Solution
Customers are advised to refer JRASERVER-71559, for updates pertaining to this vulnerability.
Vendor References
- JRASERVER-71559 -
jira.atlassian.com/browse/JRASERVER-71559
CVEs related to QID 730086
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-71559 |
|