CVE-2020-4028

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/06/2020
Last modified:
08/07/2020

Description

Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:* 8.9.1 (excluding)
cpe:2.3:a:atlassian:jira_software_data_center:*:*:*:*:*:*:*:* 8.9.1 (excluding)


References to Advisories, Solutions, and Tools