Sync with external cvelist

This commit is contained in:
David Black 2020-06-23 08:28:40 +10:00
parent 85882c4ef2
commit bded4b676b

View File

@ -1,112 +1,115 @@
{
"CVE_data_meta": {
"ASSIGNER": "security@atlassian.com",
"DATE_PUBLIC": "2020-06-01T00:00:00",
"ID": "CVE-2020-4026",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Navigator Links",
"version": {
"version_data": [
{
"version_value": "3.2.23",
"version_affected": "<"
},
{
"version_value": "4.0.0",
"version_affected": ">="
},
{
"version_value": "4.3.7",
"version_affected": "<"
},
{
"version_value": "5.0.0",
"version_affected": ">="
},
{
"version_value": "5.0.1",
"version_affected": "<"
},
{
"version_value": "5.1.0",
"version_affected": ">="
},
{
"version_value": "5.1.1",
"version_affected": "<"
}
]
}
},
{
"product_name": "Crucible",
"version": {
"version_data": [
{
"version_value": "4.8.2",
"version_affected": "<"
}
]
}
},
{
"product_name": "Fisheye",
"version": {
"version_data": [
{
"version_value": "4.8.2",
"version_affected": "<"
}
]
}
}
]
},
"vendor_name": "Atlassian"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before version 4.3.7, from version 5.0.0 before 5.0.1, and from version 5.1.0 before 5.1.1 allows remote attackers to enumerate all linked applications, including those that are restricted or otherwise hidden, through an incorrect authorization check."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Incorrect Authorization"
}
"CVE_data_meta": {
"ASSIGNER": "security@atlassian.com",
"DATE_PUBLIC": "2020-06-01T00:00:00",
"ID": "CVE-2020-4026",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Navigator Links",
"version": {
"version_data": [
{
"version_value": "3.2.23",
"version_affected": "<"
},
{
"version_value": "4.0.0",
"version_affected": ">="
},
{
"version_value": "4.3.7",
"version_affected": "<"
},
{
"version_value": "5.0.0",
"version_affected": ">="
},
{
"version_value": "5.0.1",
"version_affected": "<"
},
{
"version_value": "5.1.0",
"version_affected": ">="
},
{
"version_value": "5.1.1",
"version_affected": "<"
}
]
}
},
{
"product_name": "Crucible",
"version": {
"version_data": [
{
"version_value": "4.8.2",
"version_affected": "<"
}
]
}
},
{
"product_name": "Fisheye",
"version": {
"version_data": [
{
"version_value": "4.8.2",
"version_affected": "<"
}
]
}
}
]
},
"vendor_name": "Atlassian"
}
]
}
]
},
"references": {
"reference_data": [
{
"url": "https://jira.atlassian.com/browse/FE-7299"
},
{
"url": "https://jira.atlassian.com/browse/CRUC-8485"
}
]
}
}
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before version 4.3.7, from version 5.0.0 before 5.0.1, and from version 5.1.0 before 5.1.1 allows remote attackers to enumerate all linked applications, including those that are restricted or otherwise hidden, through an incorrect authorization check."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Incorrect Authorization"
}
]
}
]
},
"references": {
"reference_data": [
{
"url": "https://jira.atlassian.com/browse/FE-7299",
"refsource": "MISC",
"name": "https://jira.atlassian.com/browse/FE-7299"
},
{
"url": "https://jira.atlassian.com/browse/CRUC-8485",
"refsource": "MISC",
"name": "https://jira.atlassian.com/browse/CRUC-8485"
}
]
}
}