Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability.
                
            References
                    | Link | Resource | 
|---|---|
| https://jira.atlassian.com/browse/JRASERVER-71175 | Issue Tracking Vendor Advisory | 
| https://jira.atlassian.com/browse/JRASERVER-71175 | Issue Tracking Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 05:32
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://jira.atlassian.com/browse/JRASERVER-71175 - Issue Tracking, Vendor Advisory | 
Information
                Published : 2020-06-23 13:15
Updated : 2024-11-21 05:32
NVD link : CVE-2020-4028
Mitre link : CVE-2020-4028
CVE.ORG link : CVE-2020-4028
JSON object : View
Products Affected
                atlassian
- jira_software_data_center
- jira
CWE
                
                    
                        
                        CWE-203
                        
            Observable Discrepancy
