The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous malicious users to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
atlassian jira server |