CVE-2020-36231
Summary
| CVE | CVE-2020-36231 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-02 00:15:00 UTC |
| Updated | 2022-03-30 13:21:00 UTC |
| Description | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [JRASERVER-72002] Board metadata is viewable without permissions via IDOR - CVE-2020-36231 - Create and track feature requests for Atlassian products. |
MISC |
jira.atlassian.com |
Issue Tracking, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150376 Atlassian Jira Server Board metadata is viewable without permissions via IDOR (CVE-2020-36231)
- 730105 Atlassian Jira Server Insecure Direct Object References Vulnerability (JRASERVER-72002)