Authorization Flaw in Atlassian Navigator Links Affects Multiple Versions
CVE-2020-4026

4.3MEDIUM

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
3 June 2020

Summary

An authorization issue in Atlassian Navigator Links allows remote attackers to gain access to listings of all linked applications, including those that are hidden or have restricted access. This vulnerability stems from improper authentication checks in multiple versions of the product, potentially exposing sensitive information to unauthorized users.

Affected Version(s)

Crucible < 4.8.2

Fisheye < 4.8.2

Navigator Links < 3.2.23

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.