First published: Wed Jan 20 2021(Updated: )
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.14.1.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Data Center | <8.5.11 | |
Atlassian Data Center | >=8.6.0<8.13.3 | |
Atlassian Data Center | >=8.14.0<8.14.1 | |
Atlassian JIRA | <8.5.11 | |
Atlassian Jira Server | >=8.6.0<8.13.3 | |
Atlassian Jira Server | >=8.14.0<8.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-29451.
The severity of CVE-2020-29451 is medium.
The vulnerability allows remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page.
The affected versions of Atlassian Jira Server and Data Center are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.14.1.
Yes, the fix for CVE-2020-29451 is available in versions 8.5.11, 8.13.3, and 8.14.1 of Atlassian Jira Server and Data Center.