Description
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions are before version 8.13.9, and from version 8.14.0 before 8.18.0.
Remediation
References
Related Vulnerabilities
Oracle Application Server CVE-2006-0282 Vulnerability (CVE-2006-0282)
WordPress Plugin WP Migrate DB Security Bypass (0.6)
WordPress Plugin Active Directory Integration/LDAP Integration Unspecified Vulnerability (3.7.6)
Apache HTTP Server Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-40438)
WordPress Plugin Logo Carousel Cross-Site Request Forgery (1.7.4)