Information disclosure in Jira Software Server - CVE-2018-13391

 

Information disclosure in Jira Software Server - CVE-2018-13391

Published: August 28, 2018 / Updated: July 17, 2020


Vulnerability identifier: #VU31221
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-13391
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and from version 7.11.0 before version 7.11.2 allows remote attackers who can access & view an issue to obtain the email address of the reporter and assignee user of an issue despite the configured email visibility setting being set to hidden.


Affected software

Jira Software Server

How to mitigate CVE-2018-13391

Install update from vendor's website.

Jira Software Server - update to 7.11.2

External References

Related Security Bulletins