SB2020020625 - Incorrect default permissions in Atlassian JIRA



SB2020020625 - Incorrect default permissions in Atlassian JIRA

Published: February 6, 2020 Updated: July 17, 2020

Security Bulletin ID SB2020020625
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Incorrect default permissions (CVE-ID: CVE-2019-20106)

The vulnerability allows a remote authenticated user to manipulate data.

Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.


Remediation

Install update from vendor's website.