CVE-2019-20105
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1, and from version 7.1.0 before version 7.1.3 allows remote attackers who have obtained access to administrator's session to access the EditApplinkServlet resource without needing to re-authenticate to pass "WebSudo" in products that support "WebSudo" through an improper access control vulnerability.
El recurso EditApplinkServlet en el plugin Atlassian Application Links versiones anteriores a 5.4.20, desde versión 6.0.0 anterior a versión 6.0.12, desde versión 6.1.0 anterior a versión 6.1.2, desde versión 7.0.0 anterior a versión 7.0.1, y desde versión 7.1.0 anterior a versión 7.1.3, permite a atacantes remotos que han obtenido acceso a la sesión de administrador acceder al recurso EditApplinkServlet sin ser necesario volver a autenticarse para aprobar "WebSudo" en productos que admiten "WebSudo" por medio de una vulnerabilidad de control de acceso inapropiado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-12-30 CVE Reserved
- 2020-03-17 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://ecosystem.atlassian.net/browse/APL-1391 | 2020-08-24 | |
https://jira.atlassian.com/browse/JRASERVER-70526 | 2020-08-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Atlassian Search vendor "Atlassian" | Application Links Search vendor "Atlassian" for product "Application Links" | <= 5.4.20 Search vendor "Atlassian" for product "Application Links" and version " <= 5.4.20" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Application Links Search vendor "Atlassian" for product "Application Links" | >= 6.0.0 <= 6.0.12 Search vendor "Atlassian" for product "Application Links" and version " >= 6.0.0 <= 6.0.12" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Application Links Search vendor "Atlassian" for product "Application Links" | >= 6.1.0 < 6.1.2 Search vendor "Atlassian" for product "Application Links" and version " >= 6.1.0 < 6.1.2" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Application Links Search vendor "Atlassian" for product "Application Links" | >= 7.1.0 < 7.1.3 Search vendor "Atlassian" for product "Application Links" and version " >= 7.1.0 < 7.1.3" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Application Links Search vendor "Atlassian" for product "Application Links" | 7.0.0 Search vendor "Atlassian" for product "Application Links" and version "7.0.0" | - |
Affected
|