CVE-2020-14179 is an information disclosure vulnerability in Atlassian Jira Server and Data Center versions before 8.5.8 and from 8.6.0 before 8.11.1. It allows unauthenticated remote attackers to view custom field and SLA names via the /secure/QueryComponent!Default.jspa endpoint. Rated Medium (CVSS 5.3), this vulnerability is easily exploitable over the network with no user interaction, potentially exposing sensitive configuration details. While there is no evidence of active exploitation or public Metasploit/ExploitDB modules, Nuclei templates exist for detection, and it has a high EPSS score indicating a higher-than-average likelihood of exploitation. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.5.8CPE matchmatch criteria | cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:* | ||
>= 8.6.0, < 8.11.1CPE matchmatch criteria | cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:* | ||
< 8.5.8CPE matchmatch criteria | cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:* | ||
>= 8.6.0, < 8.11.1CPE matchmatch criteria | cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:* | ||
< 8.11.1CPE match | cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.