mediumREV. 01
CVE-2020-14181Atlassian Jira — Unauthenticated User Enumeration
Jira lets an unauthenticated visitor walk its user directory, which turns into the account list an attacker needs before trying passwords anywhere else.
Read the risk
THE VITAL STATS- CVSS score
- 5.3/ 10 CVSS v3.1
- EPSS probability
- 100% Likelihood of exploitation
- Attack complexity
- Low Conditions needed to exploit
- Known exploited
- Not listed
- CVE published
- 2020-09-17
- Exploit published
- Yes
- Confidence
- high
- Kill chain
- discovery
- MITRE ATT&CK
- T1190, T1087
- Severity
- medium
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attacker needsNetwork access to the instance
Behind the card
3 REFERENCES- 01CVE recordNVD recordnvd.nist.gov
- 02Vendor advisoryjira.atlassian.comjira.atlassian.com
- 03Exploitpacketstormsecurity.compacketstormsecurity.com
Field-level provenanceTRACE THE SOURCES +
Which source supports each field, when it was retrieved, and who extracted it.
| Fields | Source | Retrieved | Extractor | Confidence |
|---|---|---|---|---|
| cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_at | nvd.nist.gov | 2026-08-07 | scrty-crds-pipeline/0.1 | high |
| epss | api.first.org | 2026-08-07 | scrty-crds-pipeline/0.1 | high |
| title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisites | nvd.nist.gov | 2026-08-07 | claude-code | high |
| mitre_attack | nvd.nist.gov | 2026-09-20 | human | high |
Printing history
THE RECORD- r1Initial base card
First printing. This card has not been reprinted since publication.