Description
Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Replication settings via a Broken Access Control vulnerability in the `ReplicationSettings!default.jspa` endpoint. The affected versions are before version 8.6.0, from version 8.7.0 before 8.13.12, and from version 8.14.0 before 8.20.1.
Remediation
References
Related Vulnerabilities
WordPress Other Vulnerability (CVE-2006-0733)
Joomla Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2011-4907)
WordPress Plugin Social Media Share Buttons & Social Sharing Icons Security Bypass (1.5.1)
Internet Information Services Other Vulnerability (CVE-1999-1537)
Internet Information Services Other Vulnerability (CVE-2000-0246)