Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7fxq-g996-6g8m

Опубликовано: 09 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint. The affected versions are before version 8.19.1.

Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint. The affected versions are before version 8.19.1.

EPSS

Процентиль: 41%
0.00188
Низкий

7.5 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint. The affected versions are before version 8.19.1.

EPSS

Процентиль: 41%
0.00188
Низкий

7.5 High

CVSS3

Дефекты

CWE-287