The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://jira.atlassian.com/browse/JRASERVER-69246 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: atlassian
Published: 2019-04-30T15:28:27.874744Z
Updated: 2024-09-16T17:48:24.295Z
Reserved: 2018-12-19T00:00:00
Link: CVE-2019-3399
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-04-30T16:29:00.683
Modified: 2024-11-21T04:42:01.927
Link: CVE-2019-3399
Redhat
No data.