Unauthenticated File Access in Atlassian Crowd
CVE-2020-36240
5.3MEDIUM
Summary
The ResourceDownloadRewriteRule class in Atlassian Crowd is vulnerable to improper access control, allowing unauthenticated remote attackers to exploit the flaw and read sensitive files located within the WEB-INF and META-INF directories. This vulnerability affects versions before 4.0.4 and versions 4.1.0 up to 4.1.2. Users should ensure they maintain their systems with the latest security patches to mitigate risks associated with unauthorized data exposure.
Affected Version(s)
Crowd < 4.0.4
Crowd 4.1.0
Crowd < 4.1.2
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved