CVE-2020-4029Incorrect Authorization in Atlassian Jira Server AND Data Center

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 54.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 1
Latest updateMay 24

Description

The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, from 8.6.0 before 8.7.2, and from 8.8.0 before 8.8.1 allows remote attackers to enumerate project names via an improper authorization vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5atlassian/jira_server_and_data_centerunspecified8.5.5+4
NVDatlassian/jira_data_center8.6.08.7.2+1
NVDatlassian/jira_server8.6.08.7.2+1
NVDatlassian/jira< 8.5.5

🔴Vulnerability Details

2
GHSA
GHSA-w67p-2w4g-fgjp: The /rest/project-templates/12022-05-24
CVEList
CVE-2020-4029: The /rest/project-templates/12020-07-01
CVE-2020-4029 — Incorrect Authorization in Atlassian | cvebase