QID 150376
Date Published: 2021-10-22
QID 150376: Atlassian Jira Server Board metadata is viewable without permissions via IDOR (CVE-2020-36231)
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
The installed version of Jira Atlassian Server allow unauthenticated remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability.
Affected versions:
before version 8.5.10
from version 8.6.0 before 8.13.2
Successful exploitation would lead to disclosure of the Board metadata, which can help the attacker carry out further attacks and obtain sensitive information.
Solution
Upgrade the Atlassian Jira to new version.
Vendor References
- JRASERVER-72002 -
jira.atlassian.com/browse/JRASERVER-72002
CVEs related to QID 150376
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72002 |
|