CVE-2020-4028

CWE-2033 documents3 sources
Severity
5.3MEDIUM
EPSS
0.5%
top 36.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 23
Latest updateMay 24

Description

Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

NVDatlassian/jira< 8.9.1
CVEListV5atlassian/jira_server_and_data_centerunspecified8.9.1

🔴Vulnerability Details

2
GHSA
GHSA-pvrh-7mfr-7cr8: Versions before 82022-05-24
CVEList
CVE-2020-4028: Versions before 82020-06-23