Description
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Keyword Link Multiple Cross-Site Scripting Vulnerabilities (1.7)
Jenkins Session Fixation Vulnerability (CVE-2018-1000409)
Python Integer Overflow or Wraparound Vulnerability (CVE-2008-3144)
Drupal Core 6.x Remote Code Execution (6.0 - 6.38)
Piwigo URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-9464)