-
Public Security Vulnerability
-
Resolution: Fixed
-
Low (View bug fix roadmap)
-
8.9.0
-
None
-
5.3
-
Medium
-
CVE-2020-36235
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view.
The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.
Affected versions:
- version < 8.13.2
- 8.14.0 ≤ version < 8.14.1
Fixed versions:
- 8.13.2
- 8.14.1
- 8.15.0
[JRASERVER-71950] Mobile site reveals the summary titles of privately linked tickets - CVE-2020-36235
CVE ID | New: CVE-2020-36235 |
Security | Original: Reporter and Atlassian Staff [ 10751 ] |
Labels | New: cve-2020-36235 |
Summary | Original: Mobile site reveals the summary titles of privately linked tickets - CVE-PENDING | New: Mobile site reveals the summary titles of privately linked tickets - CVE-2020-36235 |
Security | New: Reporter and Atlassian Staff [ 10751 ] |
Security | Original: Atlassian Staff [ 10750 ] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Draft [ 12872 ] | New: Published [ 12873 ] |
Summary | Original: Mobile site reveals the summary titles of privately linked tickets | New: Mobile site reveals the summary titles of privately linked tickets - CVE-PENDING |
Description |
Original:
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an Information Disclosure vulnerability in the custom field and custom SLA names.
The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1. *Affected versions:* * version < 8.13.2 * 8.14.0 ≤ version < 8.14.1 *Fixed versions:* * 8.13.2 * 8.14.1 * 8.15.0 |
New:
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view.
The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1. *Affected versions:* * version < 8.13.2 * 8.14.0 ≤ version < 8.14.1 *Fixed versions:* * 8.13.2 * 8.14.1 * 8.15.0 |
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 5.3 => Medium severity
Exploitability Metrics
Scope Metric
Impact Metrics
https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N