Description
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature. The affected versions are before version 4.21.0.
Remediation
References
Related Vulnerabilities
WordPress Plugin Custom Global Variables Cross-Site Scripting (1.0.5)
Plone CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-5495)
Dolibarr Inadequate Encryption Strength Vulnerability (CVE-2017-7888)
WebLogic CVE-2020-14640 Vulnerability (CVE-2020-14640)
Sqlite Numeric Truncation Error Vulnerability (CVE-2025-6965)