PT-2021-11993 · Atlassian · Jira
David Black
·
Published
2021-04-01
·
Updated
2022-03-30
·
CVE-2020-36286
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Jira Server and Data Center versions 8.5.13 and earlier, versions 8.6.0 through 8.13.4, and versions 8.14.0 through 8.15.0
Jira Server versions 8.5.13 and earlier, versions 8.6.0 through 8.13.4, and versions 8.14.0 through 8.15.0
Jira Data Center versions 8.5.13 and earlier, versions 8.6.0 through 8.13.4, and versions 8.14.0 through 8.15.0
Description:
The membersOf JQL search function allows remote anonymous attackers to determine if a group exists and members of groups if they are assigned to publicly visible issue fields.
Recommendations:
For versions 8.5.13 and earlier, update to version 8.5.13 or later.
For versions 8.6.0 through 8.13.4, update to version 8.13.5 or later.
For versions 8.14.0 through 8.15.0, update to version 8.15.1 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jira