CVE-2020-14183

MEDIUM

Jira Server & Data Center < 7.13.18, 8.0.0-8.5.9, 8.6.0-8.12.1 - Information Disclosure via HTTP Headers

Title source: llm
STIX 2.1

Description

Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected versions are before version 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before 8.12.1.

References (1)

Core 1
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-71646

Scores

CVSS v3 4.3
EPSS 0.0031
EPSS Percentile 54.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
atlassian/jira < 7.13.18 (2 CPE variants)
Published Oct 06, 2020
Tracked Since Feb 18, 2026