CVE-2020-14179
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an...
- Published
- Sep 21, 2020
- Updated
- Sep 16, 2024
- Assigning CNA
- atlassian
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NHigh · next 30 days
- Percentile
- 99.5%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1.
Sources
2- CVE-2020-14179Scanner
Perl-based scanner for CVE-2020-14179 (Jira information disclosure). Scans single URLs or lists for the vulnerability, aiding in security assessment and penetration testing.
- CVE-2020-14179Scanner
Sensitive data exposure via /secure/QueryComponent!Default.jspa endpoint - CVE-2020-14179
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.