CVE-2020-4028 Information
Feb 14, 2021
cve
Description
Versions before 8.9.1 Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://jira.atlassian.com/browse/JRASERVER-71175
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: