5
CVSSv2

CVE-2020-14179

Published: 21/09/2020 Updated: 27/07/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated malicious users to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 prior to 8.11.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

atlassian jira server

atlassian jira data center

Github Repositories

JIRA"YA is a vulnerability analyzer for JIRA instances. It runs active scans to identify vulnerabilities by interacting with the host and conducting tests.

JIRA"YA - JIRA Yet Another vulnerability Analyzer by @FR13ND0x7f What is JIRA? JIRA is a popular p

CVE-2020-14179 Scanner

CVE-2020-14179 Scanner Sample scan (/CVE-2020-14179pl -u jiraatlassiancom ) OR (/CVE-2020-14179pl -u jiraatlassiancom ) List scan (/CVE-2020-14179pl -l listtxt) Show Options (/CVE-2020-14179pl) How to install and use (* linux) git clone githubcom/c0brabaghdad1/CVE-2020-14179git cd CVE-2020-14179 chmod +x CVE-2020-14179pl (/CVE-2020-14179pl

Sensitive data exposure via /secure/QueryComponent!Default.jspa endpoint - CVE-2020-14179

CVE-2020-14179 Sensitive data exposure via /secure/QueryComponent!Defaultjspa endpoint Priority: High Affects Version/s: 860 | 880 | 855 | 890 | 8100 | 8110 Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/Qu

一款用于快速验证漏洞的简易框架

R-poc 一款用于快速验证漏洞的简易框架 基于Airpoc,对其进行了改动 原项目文章:paperseebugorg/913/ 支持单/多目标,多目标写在文件列表内 暴力执行pocs目录下的所有poc对目标进行测试 可检测列表 Struts2系列 st2-045 st2-046 unauth redis-unauthpy mongodb-unauthpy zookeeper-unauthpy jenkins-u