
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (CVE-2020-36238) affects Jira Server and Data Center's /rest/api/1.0/render resource. The issue was discovered in multiple versions: before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1. The vulnerability was reported on January 27, 2021, and was fixed with the release of versions 8.5.13, 8.13.5, and 8.15.1 (Atlassian Jira).
The vulnerability is related to a missing permissions check in the /rest/api/1.0/render resource. The issue has been assigned a CVSS Score of 3.0, indicating Low severity. The vulnerability is classified under CWE-863, which relates to incorrect authorization (Atlassian Jira).
The vulnerability allows remote anonymous attackers to determine if a username is valid or not through the affected resource. This information disclosure could potentially be used as a stepping stone for further attacks by helping attackers identify valid user accounts in the system (Atlassian Jira).
Atlassian has released fixed versions to address this vulnerability. Users should upgrade to version 8.5.13 if running 8.5.x, version 8.13.5 if running 8.6.0-8.13.x, or version 8.15.1 if running 8.14.0-8.15.0 (Atlassian Jira).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."