Description
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0.
Remediation
References
Related Vulnerabilities
PHP POST file upload buffer overflow vulnerabilities
Squid Integer Overflow or Wraparound Vulnerability (CVE-2020-11945)
WordPress Plugin Cart66 Pro Arbitrary File Disclosure (1.5.3)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-1580)
phpMyFAQ Weak Password Requirements Vulnerability (CVE-2023-1753)