cvedb.io
CVE-2017-18104
MEDIUM · CVSS 5.9
EPSS exploitation probability: 0%
Published 2018-07-24T13:29:00.230 · Last modified 2026-06-17T01:12:12.557

Summary

The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to observe or otherwise intercept webhook events to learn information about changes in issues that should not be sent because they are not contained within the results of a specified JQL query.

Affected products

atlassian — jira

Does this affect you?

Add your gear to cvedb and we'll alert you only when atlassian ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.