First published: Thu Feb 04 2021(Updated: )
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Disclosure vulnerability in the /rest/api/2/customFieldOption/ endpoint. The affected versions are before version 8.15.0.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Data Center | <8.15.0 | |
Atlassian JIRA | <8.15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-36237.
The severity of CVE-2020-36237 is medium, with a severity value of 5.3.
Unauthenticated remote attackers can exploit CVE-2020-36237 by using the /rest/api/2/customFieldOption/ endpoint to view custom field options.
Affected versions of Atlassian Jira Server and Data Center are versions before 8.15.0.
Yes, you can find more information about CVE-2020-36237 at the following reference: https://jira.atlassian.com/browse/JRASERVER-72064