CVE-2020-36286
The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a group exists & members of…
Does this matter?
Lower severity and a low EPSS score (1.41%). Track it; it rarely justifies an emergency change on its own.
Description
The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a group exists & members of groups if they are assigned to publicly visible issue field.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.41% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- atlassian/data center · atlassian/jira · atlassian/jira data center · atlassian/jira server
- Source
- security@atlassian.com
References
- https://jira.atlassian.com/browse/JRASERVER-72272Vendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-72272Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.