Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Express app occurs with a server-to-server JWT or a context JWT. Atlassian Connect Express versions from 3.0.2 before 6.6.0 erroneously accept context JWTs in lifecycle endpoints (such as installation) where only server-to-server JWTs should be accepted, permitting an attacker to send authenticated re-installation events to an app.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Bitbucket atlassian-connect-express 授权问题漏洞
Vulnerability Description
Bitbucket atlassian-connect-express是Bitbucket开源的一个应用软件。用于使用Node.js创建基于Atlassian Connect的应用程序的工具包。 Bitbucket atlassian-connect-express 3.0.2版本至6.6.0版本存在安全漏洞,攻击者可利用该漏洞向应用程序发送经过身份验证的重新安装事件。
CVSS Information
N/A
Vulnerability Type
N/A