CVE-2020-36235: Medium severity atlassian jira vulnerability
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-36235.
What is the severity of CVE-2020-36235?
The severity of CVE-2020-36235 is medium with a severity value of 5.3.
How can unauthenticated remote attackers exploit CVE-2020-36235?
Unauthenticated remote attackers can exploit CVE-2020-36235 to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2020-36235?
Affected versions of Atlassian Jira Server and Data Center are before version 8.13.2, and from version 8.14.0 before 8.14.1.
Is there a fix available for CVE-2020-36235?
Yes, to fix CVE-2020-36235, upgrade to version 8.13.2 or higher, or upgrade to version 8.14.1 or higher.