Vulnerabilities > CVE-2020-4026 - Incorrect Authorization vulnerability in Atlassian Navigator Links 4.0.0/5.0.0/5.1.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before version 4.3.7, from version 5.0.0 before 5.0.1, and from version 5.1.0 before 5.1.1 allows remote attackers to enumerate all linked applications, including those that are restricted or otherwise hidden, through an incorrect authorization check.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |