-
Public Security Vulnerability
-
Resolution: Fixed
-
Low
-
8.20.8
-
Severity 2 - Major
-
5.3
-
Medium
Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers without permission to view a private project to view the project's issue creation meta information via a Broken Access Control vulnerability in the */issue/createmeta *endpoint.
The affected LTS version is 8.20.8 and the fix is not backported to this version.