Authorization Flaw in Atlassian Navigator Links Affects Multiple Versions
CVE-2020-4026
4.3MEDIUM
Summary
An authorization issue in Atlassian Navigator Links allows remote attackers to gain access to listings of all linked applications, including those that are hidden or have restricted access. This vulnerability stems from improper authentication checks in multiple versions of the product, potentially exposing sensitive information to unauthorized users.
Affected Version(s)
Crucible < 4.8.2
Fisheye < 4.8.2
Navigator Links < 3.2.23
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved