CVE-2020-36231: Medium severity atlassian jira vulnerability
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-36231.
What versions of Atlassian Jira Server and Data Center are affected by this vulnerability?
Affected versions of Atlassian Jira Server and Data Center are before version 8.5.10, and from version 8.6.0 before 8.13.2.
How can remote attackers exploit this vulnerability?
Remote attackers can exploit this vulnerability to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability.
What is the severity of this vulnerability?
The severity of this vulnerability is medium, with a severity value of 4.3.
How can I fix this vulnerability?
To fix this vulnerability, upgrade your Atlassian Jira Server or Data Center to version 8.5.10 or higher, or upgrade to version 8.13.2 or higher.