CVE-2020-14185: Medium severity atlassian jira vulnerability
Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before version 8.12.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-14185?
CVE-2020-14185 has a medium severity rating due to its potential for remote unauthenticated exploitation.
How do I fix CVE-2020-14185?
To mitigate CVE-2020-14185, update Jira Server to at least version 7.13.18 or any version in the 8.x line after 8.5.9 or 8.12.2.
What versions of Jira are affected by CVE-2020-14185?
Affected versions include Jira Server prior to 7.13.18, from 8.0.0 before 8.5.9, and from 8.6.0 before 8.12.2.
Can CVE-2020-14185 be exploited remotely?
Yes, CVE-2020-14185 allows remote unauthenticated attackers to enumerate issue keys.
What type of vulnerability is CVE-2020-14185?
CVE-2020-14185 is categorized as an authorization vulnerability due to a missing permissions check.