The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before version 4.3.7, from version 5.0.0 before 5.0.1, and from version 5.1.0 before 5.1.1 allows remote attackers to enumerate all linked applications, including those that are restricted or otherwise hidden, through an incorrect authorization check.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: atlassian
Published: 2020-06-02T23:40:12.121427Z
Updated: 2024-09-17T04:05:05.012Z
Reserved: 2019-12-30T00:00:00
Link: CVE-2020-4026
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-06-03T00:15:10.857
Modified: 2024-11-21T05:32:10.740
Link: CVE-2020-4026
Redhat
No data.