Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-66005

The bundled Atlassian Activity Streams plugin had Improper Access control inside several rest inline action resource resource - CVE-2017-9506

    XMLWordPrintable

Details

    Description

      The version of the bundled Atlassian Activity Streams plugin was vulnerable to Improper Access control. This allowed remote authenticated attackers to watch any Confluence page & receive notifications when comments are added to the watched page, and vote & watch JIRA issues that they do not have access to, although they will not receive notifications for the issue, via missing permission checks. More information about the Atlassian Activity Stream plugin issue see https://ecosystem.atlassian.net/browse/STRM-2350 .

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              dblack David Black
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: