secure/ConfigureReleaseNote.jspa in Atlassian JIRA 3.6.2-#156 allows remote attackers to obtain sensitive information via unspecified manipulations of the projectId parameter, which displays the installation path and other system information in an error message.
| Software | From | Fixed in |
|---|---|---|
| atlassian / jira | 3.6.2_156 | 3.6.2_156.x |