Description
Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projects via an Information Disclosure vulnerability in the /rest/api/latest/projectvalidate/key endpoint. The affected versions are before version 8.5.18, from version 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2023-21742 Vulnerability (CVE-2023-21742)
WordPress Plugin Easy FancyBox Cross-Site Scripting (1.8.17)
Ruby on Rails URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-22903)
WordPress Plugin Peugeot Music Arbitrary File Upload (1.0)
WordPress Plugin Sidekick Multiple Unspecified Vulnerabilities (2.2.1)