CVE-2020-36289: Medium severity atlassian data center vulnerability
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-36289?
CVE-2020-36289 is an Information Disclosure vulnerability in Atlassian Jira Server and Data Center that allows an unauthenticated user to enumerate users.
What is the severity of CVE-2020-36289?
CVE-2020-36289 has a severity level of 5.3 (medium).
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2020-36289?
Atlassian Jira Server and Data Center versions before 8.5.13, from 8.6.0 to 8.13.5, and from 8.14.0 to 8.15.1 are affected by CVE-2020-36289.
How can an unauthenticated user exploit the CVE-2020-36289 vulnerability?
An unauthenticated user can exploit the CVE-2020-36289 vulnerability by accessing the QueryComponentRendererValue!Default.jspa endpoint to enumerate users in Atlassian Jira Server and Data Center.
Is there a fix available for CVE-2020-36289?
Yes, the fix for CVE-2020-36289 is available in versions 8.5.13, 8.13.6, and 8.15.2 of Atlassian Jira Server and Data Center.