4.9
CVE-2019-20105
- EPSS 0.2%
- Veröffentlicht 17.03.2020 03:15:10
- Zuletzt bearbeitet 21.11.2024 04:38:04
- Quelle security@atlassian.com
- CVE-Watchlists
- Unerledigt
The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1, and from version 7.1.0 before version 7.1.3 allows remote attackers who have obtained access to administrator's session to access the EditApplinkServlet resource without needing to re-authenticate to pass "WebSudo" in products that support "WebSudo" through an improper access control vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Atlassian ≫ Application Links Version <= 5.4.20
Atlassian ≫ Application Links Version >= 6.0.0 <= 6.0.12
Atlassian ≫ Application Links Version >= 6.1.0 < 6.1.2
Atlassian ≫ Application Links Version >= 7.1.0 < 7.1.3
Atlassian ≫ Application Links Version7.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.419 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.