CVE-2020-36287Incorrect Authorization in Atlassian Jira Data Center

Severity
5.3MEDIUMNVD
EPSS
62.7%
top 1.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9
Latest updateMay 24

Description

The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions check.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages6 packages

CVEListV5atlassian/jira_data_centerunspecified8.13.5+2
NVDatlassian/jira_data_center8.14.08.15.1
CVEListV5atlassian/jira_serverunspecified8.13.5+2
NVDatlassian/jira_server8.14.08.15.1
NVDatlassian/jira< 8.13.5

🔴Vulnerability Details

2
GHSA
GHSA-53qj-6rvh-pv6c: The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 82022-05-24
CVEList
CVE-2020-36287: The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 82021-04-09
CVE-2020-36287 — Incorrect Authorization in Atlassian | cvebase