← Back

CVE-2020-36289

Published: May 12, 2021Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1.

Affected (6)

4 products
Data Center
Jira
Jira Data Center
Jira Server
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Before 8.5.13
Before 8.5.13
Atlassian
From 8.14.0 to 8.15.1
From 8.6.0 to 8.13.5
Atlassian
From 8.14.0 to 8.15.1
From 8.6.0 to 8.13.5

References (2)

Source: security@atlassian.com
Issue TrackingPermissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPermissions RequiredVendor Advisory

Timeline

No history available yet.