Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another users private checklist.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Jira_align | Atlassian | 11.14.0 (including) | 11.16.1 (excluding) |