
This blog details our discovery of an Insecure Direct Object Reference (IDOR) vulnerability in JIRA, a product by Atlassian. You may be familiar with Atlassian platform from our previous blog, where we discussed how we found a wormable XSS vulnerability in their web application. If you haven't already,