Vulnerabilities > Atlassian > Jira Software Data Center > 8.5.9
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-02-02 | CVE-2020-36231 | Authorization Bypass Through User-Controlled Key vulnerability in Atlassian products Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. | 4.0 |
2020-07-13 | CVE-2019-20898 | Information Exposure vulnerability in Atlassian Jira Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. | 5.0 |
2020-07-01 | CVE-2020-14165 | Incorrect Authorization vulnerability in Atlassian Jira The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obtain information about custom project avatars names via an Improper authorization vulnerability. | 5.0 |