Information disclosure in Jira Software Server - CVE-2017-18104
Published: July 30, 2018
Vulnerability details
The disclosed vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to arbitrary data are not contained within the results of a specified JQL query. A remote attacker who is able to observe or otherwise intercept webhook events can learn information about changes in issues that should not be sent.