-
Bug
-
Resolution: Fixed
-
Low
-
8.0.0, 7.6.15, 8.7.1
-
7.06
-
Severity 2 - Major
-
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper.
Affected versions:
- version < 7.13.16
- 8.0.0 ≤ version < 8.5.7
- 8.6.0 ≤ version < 8.9.2
- 8.10.0 ≤ version < 8.10.1
Fixed versions:
- 7.13.16
- 8.5.7
- 8.9.2
- 8.10.1
- 8.11.0
- was cloned as
-
JRASERVER-73811 IDOR (Insecure direct object references) in Jira 8.13.10
-
- Closed
-
[JRASERVER-71275] IDOR Disclosure of Private Project Titles - CVE-2020-14174
Link |
New:
This issue was cloned as |
Labels | Original: advisory advisory-to-release bugbounty cve-2020-14174 cvss-low idor monsters security | New: advisory advisory-released bugbounty cve-2020-14174 cvss-low idor monsters security |
Remote Link | New: This issue links to "Page (Confluence)" [ 509304 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 500273 ] |
Status | Original: Closed [ 6 ] | New: Closed [ 6 ] |
Security | Original: Atlassian Staff [ 10750 ] |
I don't see the 8.9.2 version on the download page. Should I not wait for it? I notice that 8.5.7 is also missing.
Qualys will also be flagging the older versions for which the promised fix version are still missing.
The release notes for 8.9 and 8.5 do not mention this bug as fixed.