The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://jira.atlassian.com/browse/JRASERVER-70569 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: atlassian
Published: 2020-02-06T03:10:28.034241Z
Updated: 2024-09-16T17:43:28.548Z
Reserved: 2020-01-23T00:00:00
Link: CVE-2019-20404
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-02-06T03:15:10.590
Modified: 2024-11-21T04:38:24.227
Link: CVE-2019-20404
Redhat
No data.