CVE-2019-20412: Medium severity atlassian jira vulnerability
The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerability: Workflow names; Project Key, if it is part of the workflow name; Issue Keys; Issue Types; Status Types. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-20412.
What is the severity of CVE-2019-20412?
The severity of CVE-2019-20412 is medium with a CVSS score of 5.3.
What is the affected software?
The affected software includes Atlassian Jira Server, Atlassian Jira Data Center, and Atlassian Jira Software Data Center.
What information can remote attackers enumerate through this vulnerability?
Remote attackers can enumerate Workflow names, Project Key (if it is part of the Workflow name), Issue Keys, Issue Types, and Status through this vulnerability.
Is there a fix available for CVE-2019-20412?
Yes, a fix is available for CVE-2019-20412. Please refer to the reference link for more information.