4.3
CVE-2019-20404
- EPSS 1.05%
- Veröffentlicht 06.02.2020 03:15:10
- Zuletzt bearbeitet 21.11.2024 04:38:24
- Quelle security@atlassian.com
- CVE-Watchlists
- Unerledigt
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Atlassian ≫ Jira Data Center Version >= 8.2.4 < 8.6.0
Atlassian ≫ Jira Data Center Version >= 8.6.1 < 8.7.0
Atlassian ≫ Jira Server Version >= 8.2.4 < 8.6.0
Atlassian ≫ Jira Server Version >= 8.6.1 < 8.7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.05% | 0.769 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|