Description
secure/ConfigureReleaseNote.jspa in Atlassian JIRA 3.6.2-#156 allows remote attackers to obtain sensitive information via unspecified manipulations of the projectId parameter, which displays the installation path and other system information in an error message.
Remediation
References
Related Vulnerabilities
Jboss EAP CVE-2022-1259 Vulnerability (CVE-2022-1259)
OpenSSL Improper Certificate Validation Vulnerability (CVE-2025-4575)
WordPress Plugin WP Symposium Multiple Vulnerabilities (14.05.02)
WordPress Plugin Share Buttons by AddThis Cross-Site Scripting (4.0.7)
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Request Forgery (1.23.3)