PT-2021-11976 · Atlassian · Crowd
Amit Laish
·
Published
2021-03-01
·
Updated
2021-07-21
·
CVE-2020-36240
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Crowd versions prior to 4.0.4
Crowd versions 4.1.0 through 4.1.1
Description:
The issue allows unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check in the ResourceDownloadRewriteRule class.
Recommendations:
For versions prior to 4.0.4, update to version 4.0.4 or later.
For versions 4.1.0 through 4.1.1, update to version 4.1.2 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crowd