CVE-2020-14165

MEDIUM

Jira Server/Data Center <8.9.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obtain information about custom project avatars names via an Improper authorization vulnerability.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-71185

Scores

CVSS v3 5.3
EPSS 0.0023
EPSS Percentile 45.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (2)
atlassian/jira < 8.9.0
atlassian/jira_software_data_center < 8.9.0
Published Jul 01, 2020
Tracked Since Feb 18, 2026