Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-70882

Improper authentication on Convert Sub-Task to Issue page - CVE-2019-20412

      The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerability:

      • Workflow names
      • Project Key, if it is part of the workflow name
      • Issue Keys
      • Issue Types
      • Status Types

      Affected versions:

      • version < 7.13.9
      • 7.14.0 ≤ version < 8.4.2

      Fixed versions:

      • 7.13.9
      • 8.4.2
      • 8.5.0

            [JRASERVER-70882] Improper authentication on Convert Sub-Task to Issue page - CVE-2019-20412

            David Black made changes -
            Labels Original: advisory advisory-to-release cve-2019-20412 cvss-high information-disclosure security New: advisory advisory-released cve-2019-20412 cvss-high information-disclosure security
            AB made changes -
            Summary Original: Improper authentication on Convert Sub-Task to Issue page New: Improper authentication on Convert Sub-Task to Issue page - CVE-2019-20412
            AB made changes -
            Labels Original: advisory advisory-to-release cve-in-progress cvss-high information-disclosure security New: advisory advisory-to-release cve-2019-20412 cvss-high information-disclosure security
            AB made changes -
            Labels Original: advisory advisory-to-release cvss-high information-disclosure security New: advisory advisory-to-release cve-in-progress cvss-high information-disclosure security
            set-jac-bot made changes -
            AB made changes -
            Description Original: The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerability:
             * Workflow names
             * Project Key, if it is part of the workflow name
             * Issue Keys
             * Issue Types
             * Status Types

            *Affected versions:*
             * version < 7.13.9
             * 8.0.0 ≤ version < 8.4.2

            *Fixed versions:*
             * 7.13.9
             * 8.4.2
             * 8.5.0
            New: The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerability:
             * Workflow names
             * Project Key, if it is part of the workflow name
             * Issue Keys
             * Issue Types
             * Status Types

            *Affected versions:*
             * version < 7.13.9
             * 7.14.0 ≤ version < 8.4.2

            *Fixed versions:*
             * 7.13.9
             * 8.4.2
             * 8.5.0
            Bugfix Automation Bot made changes -
            Introduced in Version New: 7.13
            AB made changes -
            Security Original: Atlassian Staff [ 10750 ]
            AB made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Needs Triage [ 10030 ] New: Closed [ 6 ]
            AB made changes -
            Description Original: Component in Atlassian Jira Server and Data Center from version 7.13.5 before version 7.13.9, from version 8.3.0 before version 8.4.2 and before version 8.5.0 allows remote attackers to IMPACT via a VULN_INFO. New: The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerability:
             * Workflow names
             * Project Key, if it is part of the workflow name
             * Issue Keys
             * Issue Types
             * Status Types

            *Affected versions:*
             * version < 7.13.9
             * 8.0.0 ≤ version < 8.4.2

            *Fixed versions:*
             * 7.13.9
             * 8.4.2
             * 8.5.0

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: