CVE-2018-13391: Infoleak
The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and from version 7.11.0 before version 7.11.2 allows remote attackers who can access & view an issue to obtain the email address of the reporter and assignee user of an issue despite the configured email visibility setting being set to hidden.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13391?
CVE-2018-13391 is classified as a high severity vulnerability that allows remote attackers to exploit Jira Server.
How do I fix CVE-2018-13391?
To mitigate CVE-2018-13391, upgrade your Jira Server to version 7.6.8 or versions later than 7.7.5, 7.8.5, 7.9.3, 7.10.3, or 7.11.2.
Which versions of Jira Server are affected by CVE-2018-13391?
CVE-2018-13391 affects Jira Server versions before 7.6.8 and from 7.7.0 before 7.7.5, 7.8.0 before 7.8.5, 7.9.0 before 7.9.3, 7.10.0 before 7.10.3, and 7.11.0 before 7.11.2.
Can I continue using an affected version of Jira Server with CVE-2018-13391?
It is not recommended to continue using an affected version of Jira Server due to the potential for remote exploitation.
What type of vulnerability is CVE-2018-13391?
CVE-2018-13391 is categorized as a remote code execution vulnerability affecting Jira Server.