First published: Wed Jul 01 2020(Updated: )
The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obtain information about custom project avatars names via an Improper authorization vulnerability.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian JIRA | <8.9.0 | |
Atlassian Jira Software Data Center | <8.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14165 is a vulnerability in Jira Server and Data Center that allows remote attackers to obtain information about custom project avatars names via an Improper authorization vulnerability.
CVE-2020-14165 affects Jira Server and Data Center versions before 8.9.0.
The severity of CVE-2020-14165 is medium with a CVSS score of 5.3.
To fix CVE-2020-14165, you should update Jira Server or Data Center to version 8.9.0 or later.
You can find more information about CVE-2020-14165 on the Atlassian Jira issue tracker: https://jira.atlassian.com/browse/JRASERVER-71185