Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-36287 PoC — Atlassian JIRA Server和Atlassian JIRA Data Center 安全漏洞

Source
Associated Vulnerability
Title:Atlassian JIRA Server和Atlassian JIRA Data Center 安全漏洞 (CVE-2020-36287)
Description:Atlassian JIRA Server和Atlassian JIRA Data Center都是澳大利亚Atlassian公司的产品。Atlassian JIRA Server是一套缺陷跟踪管理系统的服务器版本。该系统主要用于对工作中各类问题、缺陷进行跟踪管理。Atlassian JIRA Data Center是Atlassian JIRA的数据中心版本。 Jira Server 和 Jira Data Center Atlassian gadgets plugin存在安全漏洞,该漏洞允许远程匿名攻
Description
The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions check.
Readme
# CVE-2020-36287
The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions check. 

```
Affected software: Atlassian Jira Data Center, Jira Server (also tested on Jira Project Management Software)
Affected Vesrion: Before version 8.13.5, and from version 8.14.0 before version 8.15.1
CVEID: CVE-2020-36287
CVSS Score: 5.3 (Medium)
CVSS Score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Fully Patched Version: 8.13.5, 8.15.1, 8.16.0 

Link: https://site.com/secure/Dashboard.jspa
POC: https://site.com/rest/dashboards/1.0/10000/gadget/{ID}/prefs


usage: CVE-2020-36287.py [-h] [-t THREADS] [-o TIMEOUT] -u URL

optional arguments:
  -h, --help            show this help message and exit
  -t THREADS, --threads THREADS
                        number of threads (15)
  -o TIMEOUT, --timeout TIMEOUT
                        timeout
  -u URL, --url URL     url
```
File Snapshot

[4.0K] /data/pocs/06236f3ffc09f8fe5d9897d8ca1f2cba54d9ead8 ├── [2.0K] CVE-2020-36287.py ├── [1.1K] README.md └── [ 17] requirements.txt 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.