First published: Wed Jul 01 2020(Updated: )
The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, from 8.6.0 before 8.7.2, and from 8.8.0 before 8.8.1 allows remote attackers to enumerate project names via an improper authorization vulnerability.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian JIRA | <8.5.5 | |
Atlassian Jira Data Center | >=8.6.0<8.7.2 | |
Atlassian Jira Data Center | >=8.8.0<8.8.1 | |
Atlassian Jira Server | >=8.6.0<8.7.2 | |
Atlassian Jira Server | >=8.8.0<8.8.1 | |
Atlassian Jira Software Data Center | <8.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4029 is a vulnerability in Atlassian Jira Server and Data Center that allows remote attackers to enumerate project names via an improper authorization vulnerability.
CVE-2020-4029 affects Atlassian Jira Server versions before 8.7.2, Jira Data Center versions before 8.7.2, Jira Server versions before 8.8.1, and Jira Data Center versions before 8.8.1.
CVE-2020-4029 has a severity of medium with a CVSS score of 4.3.
To fix CVE-2020-4029, upgrade to Atlassian Jira Server version 8.7.2 or later, Jira Data Center version 8.7.2 or later, Jira Server version 8.8.1 or later, or Jira Data Center version 8.8.1 or later.
You can find more information about CVE-2020-4029 at the following link: [https://jira.atlassian.com/browse/JRASERVER-70926](https://jira.atlassian.com/browse/JRASERVER-70926)