5.3
CVE-2020-36235
- EPSS 0.95%
- Veröffentlicht 15.02.2021 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:29:07
- Quelle security@atlassian.com
- CVE-Watchlists
- Unerledigt
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Atlassian ≫ Jira Server Version >= 8.14.0 < 8.14.1
Atlassian ≫ Jira Software Data Center Version < 8.13.2
Atlassian ≫ Jira Software Data Center Version >= 8.14.0 < 8.14.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.95% | 0.756 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|