The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.
References
Link | Resource |
---|---|
https://jira.atlassian.com/browse/JRASERVER-70599 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-03-16 20:15
Updated : 2022-03-30 06:21
NVD link : CVE-2019-20407
Mitre link : CVE-2019-20407
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
atlassian
- jira_data_center
- jira_server