PT-2021-11976 · Atlassian · Crowd

Amit Laish

·

Published

2021-03-01

·

Updated

2021-07-21

·

CVE-2020-36240

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Crowd versions prior to 4.0.4 Crowd versions 4.1.0 through 4.1.1
Description: The issue allows unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check in the ResourceDownloadRewriteRule class.
Recommendations: For versions prior to 4.0.4, update to version 4.0.4 or later. For versions 4.1.0 through 4.1.1, update to version 4.1.2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-36240

Affected Products

Crowd