-
Public Security Vulnerability
-
Resolution: Fixed
-
Low
-
10.107.4
-
None
-
6.5
-
Medium
-
CVE-2022-36803
The MasterUserEdit API in Atlassian Jira Align before version 10.109.2 allows an authenticated attacker with the People role permission can use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox.
Affected versions:
- version < 10.109.2
Fixed versions:
- 10.109.2
[JIRAALIGN-4281] Jira Align - Improper Authorization in MasterUserEdit API - CVE-2022-36803
CVE ID | New: CVE-2022-36803 |
Resolution | New: Fixed [ 1 ] | |
Security | Original: Atlassian Staff [ 10750 ] | |
Status | Original: Draft [ 12872 ] | New: Published [ 12873 ] |
Description | Original: The MasterUserEdit API in Atlassian Jira Align before version 10.109.2 allows an authenticated attacker with the People role permission can use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox. |
New:
The MasterUserEdit API in Atlassian Jira Align before version 10.109.2 allows an authenticated attacker with the People role permission can use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox.
*Affected versions:* * version < 10.109.2 *Fixed versions:* * 10.109.2 |
Summary | Original: An Atlassian product has a security vulnerability. | New: Jira Align - Improper Authorization in MasterUserEdit API - CVE-2022-36803 |
Description |
Original:
This vulnerability affects certain versions of Atlassian Jira Align. Please describe the impact of the vulnerability here. No known vulnerability could be read off of the parent. |
New: The MasterUserEdit API in Atlassian Jira Align before version 10.109.2 allows an authenticated attacker with the People role permission can use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox. |
Labels | Original: advisory advisory-to-release dont-import security 🔢✅ | New: advisory advisory-released dont-import security 🔢✅ |
Labels | Original: advisory advisory-to-release dont-import security | New: advisory advisory-to-release dont-import security 🔢✅ |
Labels | New: advisory advisory-to-release dont-import security |