Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-69246

Information disclosure in the BrowseProjects.jspa resource - CVE-2019-3399

      The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check.

            [JRASERVER-69246] Information disclosure in the BrowseProjects.jspa resource - CVE-2019-3399

            set-jac-bot made changes -
            Said made changes -
            Labels Original: CVE-2019-3399 advisory advisory-released cvss-high security New: CVE-2019-3399 advisory advisory-released cvss-high information-disclosure security
            Clement made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 442444 ]
            David Black made changes -
            Security Original: Reporter and Atlassian Staff [ 10751 ]
            David Black made changes -
            Security New: Reporter and Atlassian Staff [ 10751 ]
            David Black made changes -
            Labels Original: CVE-2019-3399 advisory advisory-to-release cvss-high security New: CVE-2019-3399 advisory advisory-released cvss-high security
            David Black made changes -
            Labels Original: advisory advisory-to-release cvss-high security New: CVE-2019-3399 advisory advisory-to-release cvss-high security
            David Black made changes -
            Summary Original: Information disclosure in the BrowseProjects.jspa resource - CVE-2019-3399. New: Information disclosure in the BrowseProjects.jspa resource - CVE-2019-3399
            David Black made changes -
            Summary Original: Information disclosure in the BrowseProjects.jspa resource - CVE-2019-CVE-2019-3399. New: Information disclosure in the BrowseProjects.jspa resource - CVE-2019-3399.
            David Black made changes -
            Summary Original: Information disclosure in the BrowseProjects.jspa resource - CVE-2019-PENDING New: Information disclosure in the BrowseProjects.jspa resource - CVE-2019-CVE-2019-3399.

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: