Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.
2020-02-06T03:15:10.200
2024-11-21T04:38:04.510
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:P/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | atlassian | jira | < 7.13.12 | Yes |
Application | atlassian | jira_data_center | < 8.5.4 | Yes |
Application | atlassian | jira_data_center | 8.6.0 | Yes |
Application | atlassian | jira_server | < 8.5.4 | Yes |
Application | atlassian | jira_server | 8.6.0 | Yes |
Application | atlassian | jira_software_data_center | < 7.13.12 | Yes |