CVE-2020-14183
MEDIUMJira Server & Data Center < 7.13.18, 8.0.0-8.5.9, 8.6.0-8.12.1 - Information Disclosure via HTTP Headers
Title source: llmDescription
Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected versions are before version 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before 8.12.1.
References (1)
Core 1
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-71646
Scores
CVSS v3
4.3
EPSS
0.0031
EPSS Percentile
54.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (1)
atlassian/jira
< 7.13.18 (2 CPE variants)
Published
Oct 06, 2020
Tracked Since
Feb 18, 2026