Description
The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions check.
Related CPE's
Vulnerable
Vulnerable
Vulnerable
References
https://jira.atlassian.com/browse/JRASERVER-72258
Vendor Advisory
https://jira.atlassian.com/browse/JRASERVER-72258
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
5.3 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2021-04-09T00:15:12.960Z
4 years agoLast modified
2024-11-21T04:29:13.030Z
1 year ago