PT-2021-11993 · Atlassian · Jira

David Black

·

Published

2021-04-01

·

Updated

2022-03-30

·

CVE-2020-36286

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Jira Server and Data Center versions 8.5.13 and earlier, versions 8.6.0 through 8.13.4, and versions 8.14.0 through 8.15.0 Jira Server versions 8.5.13 and earlier, versions 8.6.0 through 8.13.4, and versions 8.14.0 through 8.15.0 Jira Data Center versions 8.5.13 and earlier, versions 8.6.0 through 8.13.4, and versions 8.14.0 through 8.15.0
Description: The membersOf JQL search function allows remote anonymous attackers to determine if a group exists and members of groups if they are assigned to publicly visible issue fields.
Recommendations: For versions 8.5.13 and earlier, update to version 8.5.13 or later. For versions 8.6.0 through 8.13.4, update to version 8.13.5 or later. For versions 8.14.0 through 8.15.0, update to version 8.15.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-36286

Affected Products

Jira