ZeroHour

CVE-2019-20404

CVSS 3.1
4.3 medium
EPSS
1%p69
Published
()
Modified
Description

The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.

Vendors
atlassian
Products
jira data center, jira server
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.