Description
Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.
Problem types
Improper Authorization
Product status
>= 11.14.0
>= 11.14.1
>= 11.15.0
>= 11.15.1
>= 11.16.0
>= 11.16.1
Credits
Frank Lycops, NATO Cyber Security Centre
References
jira.atlassian.com/browse/JIRAALIGN-8640