Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qx4-m255-p25g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check.

The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check.

EPSS

Процентиль: 68%
0.00573
Низкий

7.5 High

CVSS3

Дефекты

CWE-862
CWE-863

Связанные уязвимости

CVSS3: 7.5
nvd
около 6 лет назад

The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check.

EPSS

Процентиль: 68%
0.00573
Низкий

7.5 High

CVSS3

Дефекты

CWE-862
CWE-863