QID 730111
Date Published: 2021-06-14
QID 730111: Atlassian Jira Server Security Vulnerability (JRASERVER-71696)
Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
Affected by below vulnerability:
CVE-2020-14185: Unauthenticated user can Enumerate Issue Keys.
Affected version:
Atlassian Jira Server version before 7.13.18
Atlassian Jira Server from version 8.0.0 before 8.5.9
Atlassian Jira Server from version 8.6.0 before 8.12.2
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource.
Solution
Customers are advised to refer JRASERVER-71696 for updates pertaining to this vulnerability.
Vendor References
- JRASERVER-71696 -
jira.atlassian.com/browse/JRASERVER-71696
CVEs related to QID 730111
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-71696 |
|