Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
CVE-2020-36287 — The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions check. | Kitploit
Ferramentas/GitHubGitHub/f4rber/cve-2020-36287
Vulnerability AnalysisExploitationInformation GatheringWeb SecurityPenetration TestingMisconfiguration
GitHubf4rber/cve-2020-36287

CVE-2020-36287

Ver Repositório
3há 5 anosAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →

Sobre

The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions check.

Compartilhar

CVE-2020-36287

O recurso de preferências de gadgets do dashboard do plugin de gadgets da Atlassian usado no Jira Server e no Jira Data Center antes da versão 8.13.5, e da versão 8.14.0 antes da versão 8.15.1 permite que atacantes anônimos remotos obtenham configurações relacionadas a gadgets através de uma verificação de permissão ausente.

root@kitploit:~
Software afetado: Atlassian Jira Data Center, Jira Server (também testado no Jira Project Management Software)
Versão afetada: Antes da versão 8.13.5, e da versão 8.14.0 antes da versão 8.15.1
CVEID: CVE-2020-36287
Pontuação CVSS: 5.3 (Médio)
Pontuação CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Versão totalmente corrigida: 8.13.5, 8.15.1, 8.16.0

Link: https://site.com/secure/Dashboard.jspa
PoC: https://site.com/rest/dashboards/1.0/10000/gadget/{ID}/prefs


uso: CVE-2020-36287.py [-h] [-t THREADS] [-o TIMEOUT] -u URL

argumentos opcionais:
  -h, --help            mostra esta mensagem de ajuda e sai
  -t THREADS, --threads THREADS
                        número de threads (15)
  -o TIMEOUT, --timeout TIMEOUT
                        tempo limite
  -u URL, --url URL     url
Baixar ferramenta