Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-72064

Custom field options are exposed via an unauthenticated REST API endpoint - CVE-2020-36237

    • 5
    • Medium
    • CVE-2020-36237

      Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Disclosure vulnerability in the /rest/api/2/customFieldOption/ endpoint.

       

      The affected versions are before version 8.15.0.

       

      Affected versions:

      • version < 8.15.0

      Fixed versions:

      • 8.15.0  

          Form Name

            [JRASERVER-72064] Custom field options are exposed via an unauthenticated REST API endpoint - CVE-2020-36237

            Qualys is flagging this issue as QID 150370.

             

            Russell Berry added a comment - Qualys is flagging this issue as QID 150370.  
            Geoff made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 589044 ]
            Security Metrics Bot made changes -
            CVE ID New: CVE-2020-36237

            Ravi Dahal added a comment -

            Is this Fix available for LTS 8.13.x?

            Ravi Dahal added a comment - Is this Fix available for LTS 8.13.x?
            Andriy Yakovlev [Atlassian] made changes -
            Remote Link New: This issue links to "JSEC-122 (JIRA Server (Bulldog))" [ 571714 ]
            Andriy Yakovlev [Atlassian] made changes -
            Labels Original: CVE-2020-36237 advisory advisory-to-release dont-import security New: CVE-2020-36237 advisory advisory-to-release dont-import lts-backport security

            Any news about a fix in the Long Term Support Version

            Fritz Meier added a comment - Any news about a fix in the Long Term Support Version

            Why is this not fixed for 8.13.x?

            LPS Config Team added a comment - Why is this not fixed for 8.13.x?

            More than three months and two updates of the Long Term Support release later and this is still not fixed.

            Russell Berry added a comment - More than three months and two updates of the Long Term Support release later and this is still not fixed.

            Will this be backported to 8.13.x?

            Emilio Palmiero added a comment - Will this be backported to 8.13.x?

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              19 Start watching this issue

                Created:
                Updated:
                Resolved: