Medium severity5.3NVD Advisory· Published Feb 15, 2021· Updated Jun 17, 2026
CVE-2020-36237
CVE-2020-36237
Description
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Disclosure vulnerability in the /rest/api/2/customFieldOption/ endpoint. The affected versions are before version 8.15.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6<8.15.0+ 1 more
- (no CPE)range: <8.15.0
- (no CPE)range: unspecified
<8.15.0+ 1 more
- (no CPE)range: <8.15.0
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
1- jira.atlassian.com/browse/JRASERVER-72064nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.