Rapid7 Vulnerability & Exploit Database

Atlassian JIRA: Improper Input Validation (CVE-2020-36231)

Back to Search

Atlassian JIRA: Improper Input Validation (CVE-2020-36231)

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
02/02/2021
Created
02/13/2021
Added
02/12/2021
Modified
02/12/2021

Description

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2.

Solution(s)

  • atlassian-jira-upgrade-8_13_2
  • atlassian-jira-upgrade-8_5_10

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;