CVE-2020-14181: Infoleak
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, and from version 8.6.0 before 8.12.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-14181?
The severity of CVE-2020-14181 is medium.
How does CVE-2020-14181 impact Atlassian Jira Server and Data Center?
CVE-2020-14181 allows an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint in affected versions of Atlassian Jira Server and Data Center.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2020-14181?
The versions affected by CVE-2020-14181 are before version 7.13.6, from version 8.0.0 before 8.5.7, and from version 8.6.0 before 8.12.0.
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2020-14181?
The Common Weakness Enumeration (CWE) ID associated with CVE-2020-14181 is CWE-200.
Are there any references for CVE-2020-14181?
Yes, you can find references for CVE-2020-14181 at the following links: http://packetstormsecurity.com/files/161730/Atlassian-JIRA-8.11.1-User-Enumeration.html, https://jira.atlassian.com/browse/JRASERVER-71560.