-
Public Security Vulnerability
-
Resolution: Fixed
-
Low (View bug fix roadmap)
-
7.13.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.7.0, 8.8.0, 8.9.0, 8.10.0, 8.11.0, 8.12.0, 8.13.0
-
None
-
3
-
Low
-
CVE-2020-36231
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability.
The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2.
Affected versions:
- version < 8.5.10
- 8.6.0 ≤ version < 8.13.2
Fixed versions:
- 8.5.10
- 8.13.2
- 8.14.0
[JRASERVER-72002] Board metadata is viewable without permissions via IDOR - CVE-2020-36231
CVE ID | New: CVE-2020-36231 |
Security | Original: Atlassian Staff [ 10750 ] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Draft [ 12872 ] | New: Published [ 12873 ] |
Labels | Original: advisory advisory-to-release dont-import security | New: CVE-2020-36231 advisory advisory-to-release dont-import security |
Summary | Original: Board metadata is viewable without permissions via IDOR - CVE-PENDING | New: Board metadata is viewable without permissions via IDOR - CVE-2020-36231 |
Summary | Original: Board metadata is viewable without permissions via IDOR | New: Board metadata is viewable without permissions via IDOR - CVE-PENDING |
Summary | Original: Board metadata is viewable without permissions due to broken access control | New: Board metadata is viewable without permissions via IDOR |
I echo Ryan's inquiry. Do we have a workaround for this fix? We just upgraded to Jira Data Center 8.5.9 and will not be upgrading to the next LTS version anytime soon. A workaround for this matter will be much appreciated.