Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-72002

Board metadata is viewable without permissions via IDOR - CVE-2020-36231

    • 3
    • Low
    • CVE-2020-36231

       

      Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability.

       

      The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2.

       

      Affected versions:

      • version < 8.5.10
      • 8.6.0 ≤ version < 8.13.2

      Fixed versions:

      • 8.5.10
      • 8.13.2
      • 8.14.0  

            [JRASERVER-72002] Board metadata is viewable without permissions via IDOR - CVE-2020-36231

            Security Metrics Bot made changes -
            CVE ID New: CVE-2020-36231

            I echo Ryan's inquiry.  Do we have a workaround for this fix?  We just upgraded to Jira Data Center 8.5.9 and will not be upgrading to the next LTS version anytime soon.  A workaround for this matter will be much appreciated.

            Wansze Kong added a comment - I echo Ryan's inquiry.  Do we have a workaround for this fix?  We just upgraded to Jira Data Center 8.5.9 and will not be upgrading to the next LTS version anytime soon.  A workaround for this matter will be much appreciated.

            Is this vulnerability exploitable by unauthenticated sessions, or just to authenticated users?

            Is there a workaround other than upgrading to a patched version?

            Ryan Hammond added a comment - Is this vulnerability exploitable by unauthenticated sessions, or just to authenticated users? Is there a workaround other than upgrading to a patched version?
            AB made changes -
            Security Original: Atlassian Staff [ 10750 ]
            AB made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Draft [ 12872 ] New: Published [ 12873 ]
            AB made changes -
            Labels Original: advisory advisory-to-release dont-import security New: CVE-2020-36231 advisory advisory-to-release dont-import security
            AB made changes -
            Summary Original: Board metadata is viewable without permissions via IDOR - CVE-PENDING New: Board metadata is viewable without permissions via IDOR - CVE-2020-36231
            AB made changes -
            Summary Original: Board metadata is viewable without permissions via IDOR New: Board metadata is viewable without permissions via IDOR - CVE-PENDING

            AB added a comment -

            This is an independent assessment and you should evaluate its applicability to your own IT environment.

            CVSS v3 score: 3.5 => Low severity

            Exploitability Metrics

            Attack Vector Network
            Attack Complexity Low
            Privileges Required Low
            User Interaction Required

            Scope Metric

            Scope Unchanged

            Impact Metrics

            Confidentiality Low
            Integrity None
            Availability None

             

            AB added a comment - This is an independent assessment and you should evaluate its applicability to your own IT environment. CVSS v3 score: 3.5 => Low severity Exploitability Metrics Attack Vector Network Attack Complexity Low Privileges Required Low User Interaction Required Scope Metric Scope Unchanged Impact Metrics Confidentiality Low Integrity None Availability None  
            AB made changes -
            Summary Original: Board metadata is viewable without permissions due to broken access control New: Board metadata is viewable without permissions via IDOR

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: