The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.
References
Link Resource
https://jira.atlassian.com/browse/JRASERVER-70569 Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: atlassian

Published: 2020-02-04T00:00:00

Updated: 2020-02-06T03:10:27

Reserved: 2020-01-23T00:00:00


Link: CVE-2019-20404

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-02-06T03:15:10.590

Modified: 2022-03-30T13:21:18.763


Link: CVE-2019-20404

JSON object: View

cve-icon Redhat Information

No data.