Unauthenticated File Access in Atlassian Crowd
CVE-2020-36240

5.3MEDIUM

Key Information:

Vendor
Atlassian
Status
Vendor
CVE Published:
1 March 2021

Summary

The ResourceDownloadRewriteRule class in Atlassian Crowd is vulnerable to improper access control, allowing unauthenticated remote attackers to exploit the flaw and read sensitive files located within the WEB-INF and META-INF directories. This vulnerability affects versions before 4.0.4 and versions 4.1.0 up to 4.1.2. Users should ensure they maintain their systems with the latest security patches to mitigate risks associated with unauthorized data exposure.

Affected Version(s)

Crowd < 4.0.4

Crowd 4.1.0

Crowd < 4.1.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.