PT-2020-17840 · Atlassian · Navigator Links

Published

2020-06-02

·

Updated

2020-06-05

·

CVE-2020-4026

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Atlassian Navigator Links versions 3.3.22 and earlier Atlassian Navigator Links versions 4.0.0 through 4.3.6 Atlassian Navigator Links versions 5.0.0 Atlassian Navigator Links versions 5.1.0
Description The CustomAppsRestResource list resource in Atlassian Navigator Links allows remote attackers to enumerate all linked applications, including those that are restricted or otherwise hidden, through an incorrect authorization check.
Recommendations For versions 3.3.22 and earlier, update to version 3.3.23 or later. For versions 4.0.0 through 4.3.6, update to version 4.3.7 or later. For version 5.0.0, update to version 5.0.1 or later. For version 5.1.0, update to version 5.1.1 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4026

Affected Products

Navigator Links