The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.
References
Configurations
Information
Published : 2019-09-11 14:15
Updated : 2019-09-16 19:15
NVD link : CVE-2019-14995
Mitre link : CVE-2019-14995
JSON object : View
Products Affected
atlassian
- jira
CWE
CWE-276
Incorrect Default Permissions
