The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.
References
Link | Resource |
---|---|
https://jira.atlassian.com/browse/JRASERVER-70599 | Issue Tracking Vendor Advisory |
https://jira.atlassian.com/browse/JRASERVER-70599 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:38
Type | Values Removed | Values Added |
---|---|---|
References | () https://jira.atlassian.com/browse/JRASERVER-70599 - Issue Tracking, Vendor Advisory |
Information
Published : 2020-03-17 03:15
Updated : 2024-11-21 04:38
NVD link : CVE-2019-20407
Mitre link : CVE-2019-20407
CVE.ORG link : CVE-2019-20407
JSON object : View
Products Affected
atlassian
- jira_data_center
- jira_server
CWE
CWE-862
Missing Authorization