The /rest/api/1.0/render resource in Jira Server and Data Center before...
Vulnerability Description
The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a username is valid or not via a missing permissions check.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-36238
Credits & Attribution
No credits recorded in the NVD database.
More from Atlassian
View All →Affected Vendor
Atlassian
View all reports →