CVE-2019-8443 Information
Feb 14, 2021
cve
Description
The ViewUpgrades resource in Jira before version 7.13.4 from version 8.0.0 before version 8.0.4 and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator’s session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass \WebSudo\ through an improper access control vulnerability.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/108458 https://jira.atlassian.com/browse/JRASERVER-69240
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.1
Share on: