CVE-2020-4028

MEDIUM

Jira < 8.9.1 - Unauthenticated Information Disclosure via 404 Response

Title source: llm
STIX 2.1

Description

Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-71175

Scores

CVSS v3 5.3
EPSS 0.0035
EPSS Percentile 57.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-203
Status published
Products (2)
atlassian/jira < 8.9.1
atlassian/jira_software_data_center < 8.9.1
Published Jun 23, 2020
Tracked Since Feb 18, 2026