QID 730501
Date Published: 2022-05-26
QID 730501: Atlassian Jira Information Disclosure Vulnerability (JRASERVER-72000)
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
CVE-2020-29451: The installed version of Jira Atlassian Server allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page.
Affected versions:
Atlassian Jira Service and Data Center versions prior to 8.5.11
Atlassian Jira Service and Data Center versions from 8.6.0 prior to 8.13.3
Atlassian Jira Service and Data Center versions from 8.14.0 prior to 8.14.1
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Successful exploitation of this vulnerability may allow an attacker to enumerate unauthorized Jira projects.
- JRASERVER-72000 -
jira.atlassian.com/browse/JRASERVER-72000
CVEs related to QID 730501
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72000 |
|