PT-2020-14726 · Atlassian · Gantt-Chart For Jira
Sebastian Auwaerter
·
Published
2020-08-04
·
Updated
2025-07-25
·
CVE-2020-15943
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Gantt-Chart for Jira versions prior to 5.5.4
Description
An issue in the Gantt-Chart module allows authenticated attackers to read and write to the module configuration of other users due to a missing privilege check. This can also be used to deliver an XSS payload to other users' dashboards.
Recommendations
For versions prior to 5.5.4, update to version 5.5.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the Gantt-Chart module to minimize the risk of exploitation.
Exploit
Fix
Missing Authorization
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gantt-Chart For Jira