Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-71498

Project enumeration through /browse.PROJECTKEY - CVE-2020-14178

      Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint.

      Affected versions:

      • version < 7.13.17
      • 7.14.0 ≤ version < 8.5.8
      • 8.6.0 ≤ version < 8.12.0

      Fixed versions:

      • 7.13.17
      • 8.5.8
      • 8.12.0
      • 8.13.0

            [JRASERVER-71498] Project enumeration through /browse.PROJECTKEY - CVE-2020-14178

            Wesley Nery made changes -
            Link New: This issue was cloned as JRASERVER-74532 [ JRASERVER-74532 ]
            David Black made changes -
            Labels Original: advisory advisory-to-release cve-2020-14178 cvss-medium info_leak infoleak information-disclosure information-leak resolved-in-vf security security-imported New: advisory advisory-released cve-2020-14178 cvss-medium info_leak infoleak information-disclosure information-leak resolved-in-vf security security-imported
            Security Metrics Bot made changes -
            Labels Original: advisory advisory-to-release cve-2020-14178 cvss-medium info_leak infoleak information-disclosure information-leak security security-imported New: advisory advisory-to-release cve-2020-14178 cvss-medium info_leak infoleak information-disclosure information-leak resolved-in-vf security security-imported
            Kurt Klinner made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 507029 ]
            Mark Lang made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 504916 ]
            Mark Lang made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 503785 ]
            AB made changes -
            Security Original: Atlassian Staff [ 10750 ]
            AB made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Needs Triage [ 10030 ] New: Closed [ 6 ]
            AB made changes -
            Summary Original: Project enumeration through /browse.PROJECTKEY - CVE-PENDING New: Project enumeration through /browse.PROJECTKEY - CVE-2020-14178
            AB made changes -
            Labels Original: advisory advisory-to-release cve-in-progress cvss-medium info_leak infoleak information-disclosure information-leak security security-imported New: advisory advisory-to-release cve-2020-14178 cvss-medium info_leak infoleak information-disclosure information-leak security security-imported

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: