CVE-2018-13400 Information
Feb 14, 2021
cve
Description
Several administrative resources in Atlassian Jira before version 7.6.9 from version 7.7.0 before version 7.7.5 from version 7.8.0 before version 7.8.5 from version 7.9.0 before version 7.9.3 from version 7.10.0 before version 7.10.3 from version 7.11.0 before version 7.11.3 from version 7.12.0 before version 7.12.3 and before version 7.13.1 allow remote attackers who have obtained access to administrator’s session to access certain administrative resources without needing to re-authenticate to pass \WebSudo\ through an improper access control vulnerability.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Reference
http://www.securityfocus.com/bid/105751 https://jira.atlassian.com/browse/JRASERVER-68138
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
4.7
Share on: