Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-69246

Information disclosure in the BrowseProjects.jspa resource - CVE-2019-3399

      The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check.

            [JRASERVER-69246] Information disclosure in the BrowseProjects.jspa resource - CVE-2019-3399

            set-jac-bot made changes -
            Said made changes -
            Labels Original: CVE-2019-3399 advisory advisory-released cvss-high security New: CVE-2019-3399 advisory advisory-released cvss-high information-disclosure security
            Clement made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 442444 ]

            Hi security+atlassian1282683442,
            As per the cvss score above authentication is not required.

            David Black added a comment - Hi security+atlassian1282683442 , As per the cvss score above authentication is not required.

            Hi,
            Can anyone confirm if this vulnerability can be exploited by non authenticated users?
            Thank you.

            Kind regards,
            Rodolfo

            Security Team at Clearvision added a comment - Hi, Can anyone confirm if this vulnerability can be exploited by non authenticated users? Thank you. Kind regards, Rodolfo
            David Black made changes -
            Security Original: Reporter and Atlassian Staff [ 10751 ]
            David Black made changes -
            Security New: Reporter and Atlassian Staff [ 10751 ]
            David Black made changes -
            Labels Original: CVE-2019-3399 advisory advisory-to-release cvss-high security New: CVE-2019-3399 advisory advisory-released cvss-high security
            David Black made changes -
            Labels Original: advisory advisory-to-release cvss-high security New: CVE-2019-3399 advisory advisory-to-release cvss-high security
            David Black made changes -
            Summary Original: Information disclosure in the BrowseProjects.jspa resource - CVE-2019-3399. New: Information disclosure in the BrowseProjects.jspa resource - CVE-2019-3399

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: