S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-14179 Scanner

CVE-2020-14179 scanner - Information Disclosure vulnerability in Atlassian Jira

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
6
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-14179
5.3
CVSS

Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Jira Serverby Atlassian
AFFECTED< 8.5.8SAFE ✓≥ 8.5.8
Updated Aug 21, 2026View on NVD →
Detail

Atlassian Jira is a software product that is widely used for project management, issue tracking, and bug tracking. It allows users to plan, track, and manage tasks within their company, and it is an essential tool for software developers and IT professionals. Jira is a customizable platform that allows users to create their workflows, dashboards, and custom fields. This software is often used by companies to manage their projects, track progress, and improve workflow management.

CVE-2020-14179 is an Information Disclosure vulnerability found in Atlassian Jira Server and Data Center versions before 8.5.8, and from version 8.6.0 before 8.11.1. This vulnerability allows remote, unauthenticated attackers to view custom field names and custom Service Level Agreement (SLA) names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. An attacker can exploit this vulnerability to access sensitive information such as custom field names and SLA names without being authenticated, which can put sensitive company information at risk.

When exploited, CVE-2020-14179 can allow an attacker to obtain valuable information that can be used for nefarious purposes. For example, an attacker could use this information to launch further attacks on the company or to sell the information on the black market. This vulnerability can also lead to an unauthorized disclosure of sensitive data, which can have serious consequences for the company. This vulnerability should, therefore, be taken seriously, and precautions must be taken to protect against it.

s4e.io is a platform that provides users with access to pro features that help them quickly and easily detect vulnerabilities in their digital assets. With the pro features of this platform, users can scan their web applications and networks for any vulnerabilities that may be present. The platform also provides users with remediation advice and regular security updates to ensure that their assets are always secure. By emphasizing the benefits of this platform, users can be assured that their digital assets are always secure.

 

REFERENCES

 

Solution Advice

To protect against CVE-2020-14179, users should take the following precautions: - Upgrade to a fixed version of Jira Server and Data Center.

  • Apply patches or updates provided by Atlassian.
  • Configure firewalls and other security measures to block unauthorized access to the /secure/QueryComponent!Default.jspa endpoint.
  • Monitor the network for unauthorized access attempts.
  • Conduct regular security audits to identify and address vulnerabilities in the system.

Fixed versions:

  • 7.13.16
  • 8.5.7
  • 8.12.0

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-14179 scanner - Information Disclosure vulnerability in Atlassian Jira | S4E