Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qr6q-3xcr-gfvw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.

The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.

EPSS

Процентиль: 64%
0.00472
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-276
CWE-862

Связанные уязвимости

CVSS3: 5.3
nvd
больше 6 лет назад

The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.

EPSS

Процентиль: 64%
0.00472
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-276
CWE-862