CVE-2020-14179: Medium severity atlassian data center vulnerability
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Atlassian Jira vulnerability?
The vulnerability ID is CVE-2020-14179.
What is the severity rating of CVE-2020-14179?
The severity rating of CVE-2020-14179 is medium.
How can remote attackers exploit CVE-2020-14179 in Atlassian Jira?
Remote unauthenticated attackers can exploit CVE-2020-14179 in Atlassian Jira by viewing custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2020-14179?
Versions before 8.5.8 and from 8.6.0 to 8.11.1 of Atlassian Jira Server and Data Center are affected by CVE-2020-14179.
Is there a fix available for CVE-2020-14179?
Yes, upgrading to version 8.5.8 or higher for Atlassian Jira Server and Data Center will fix CVE-2020-14179.