CVE-2020-14165: Medium severity Atlassian Jira vulnerability
The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obtain information about custom project avatars names via an Improper authorization vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14165?
CVE-2020-14165 is a vulnerability in Jira Server and Data Center that allows remote attackers to obtain information about custom project avatars names via an Improper authorization vulnerability.
How does CVE-2020-14165 affect Jira?
CVE-2020-14165 affects Jira Server and Data Center versions before 8.9.0.
What is the severity of CVE-2020-14165?
The severity of CVE-2020-14165 is medium with a CVSS score of 5.3.
How can I fix CVE-2020-14165 in Jira?
To fix CVE-2020-14165, you should update Jira Server or Data Center to version 8.9.0 or later.
Where can I find more information about CVE-2020-14165?
You can find more information about CVE-2020-14165 on the Atlassian Jira issue tracker: https://jira.atlassian.com/browse/JRASERVER-71185