The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, from 8.6.0 before 8.7.2, and from 8.8.0 before 8.8.1 allows remote attackers to enumerate project names via an improper authorization vulnerability.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://jira.atlassian.com/browse/JRASERVER-70926 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: atlassian
Published: 2020-07-01T01:35:29.763354Z
Updated: 2024-09-16T17:54:34.534Z
Reserved: 2019-12-30T00:00:00
Link: CVE-2020-4029
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-07-01T02:15:12.413
Modified: 2024-11-21T05:32:11.070
Link: CVE-2020-4029
Redhat
No data.