CVE-2019-20404
CVE-2019-20404
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
06 Feb 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.
Affected products
Atlassian · Jira ServerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →