Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-69240

Authorisation bypass in the ViewUpgrades resource - CVE-2019-8443

      The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability.

          Form Name

            [JRASERVER-69240] Authorisation bypass in the ViewUpgrades resource - CVE-2019-8443

            set-jac-bot made changes -
            Said made changes -
            Labels Original: CVE-2019-8443 advisory advisory-released cvss-medium security New: CVE-2019-8443 advisory advisory-released basm cvss-medium improper-authentication security
            Clement made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 442518 ]
            Przemyslaw Czuj (Inactive) made changes -
            Fix Version/s Original: 8.0.4 [ 85893 ]
            chucktalk made changes -
            Remote Link Original: This issue links to "Page (Confluence)" [ 431419 ]
            chucktalk made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 431427 ]
            chucktalk made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 431419 ]
            chucktalk made changes -
            Remote Link Original: This issue links to "Page (Confluence)" [ 431410 ] New: This issue links to "Page (Confluence)" [ 431410 ]
            chucktalk made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 431410 ]
            David Black made changes -
            Labels Original: CVE-2019-8443 advisory advisory-to-release cvss-medium security New: CVE-2019-8443 advisory advisory-released cvss-medium security

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: