Information disclosure in Jira Software - CVE-2017-18104
Published: July 30, 2018
Jira Software
Detailed vulnerability description
The disclosed vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to arbitrary data are not contained within the results of a specified JQL query. A remote attacker who is able to observe or otherwise intercept webhook events can learn information about changes in issues that should not be sent.