#VU18401 Improper access control in Jira Software - CVE-2019-3399
Published: May 6, 2019 / Updated: May 6, 2019
Jira Software
Atlassian
Description
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to absent access restrictions when displaying information for archived projects within the BrowseProjects.jspa resource. A remote non-authenticated attacker can view contents of all archived projects.
Example:
http://[host]/jira/secure/BrowseProjects.jspa?selectedCategory=archived&selectedProjectType=all&s=view_archived_projects