-
Public Security Vulnerability
-
Resolution: Fixed
-
Low
-
8.5.0, 8.6.0, 7.13.17
-
None
-
3.7
-
Low
-
CVE-2020-14185
Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource.
The affected versions are before 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before version 8.12.2.
Affected versions:
- version < 7.13.18
- 8.0.0 ≤ version < 7.13.18
- 8.6.0 ≤ version < 8.12.2
Fixed versions:
- 7.13.18
- 8.5.9
- 8.12.2
- relates to
-
JRASERVER-72010 Unauthenticated information leakage of temporary files and project keys - CVE-2021-26069
-
- Published
-
-
JSEC-130 You do not have permission to view this issue
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 3.7 => Low severity
Exploitability Metrics
Scope Metric
Impact Metrics
https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N