CVE-2019-8443

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
22/05/2019
Last modified:
22/04/2022

Description

The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:* 7.13.4 (excluding)
cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:* 8.0.0 (including) 8.0.4 (excluding)
cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:* 8.1.0 (including) 8.1.1 (excluding)