
CVE-2022-36803
https://notcve.org/view.php?id=CVE-2022-36803
14 Oct 2022 — The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox. La API MasterUserEdit en Atlassian Jira Align Server versiones anteriores a 10.109.2, permite a un atacante autenticado con el permiso de rol People usar la API MasterUserEdit para modificar el rol de cualquier usuario a Super Admin.... • https://jira.atlassian.com/browse/JIRAALIGN-4281 • CWE-276: Incorrect Default Permissions •

CVE-2022-36802
https://notcve.org/view.php?id=CVE-2022-36802
14 Oct 2022 — The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery. This can be exploited by a remote, unauthenticated attacker with Super Admin privileges by sending a specially crafted HTTP request. La API ManageJiraConnectors en Atlassian Jira Align versiones anteriores a 10.109.2, permite a atacantes remotos explotar este problema para acceder a recursos de red internos por medi... • https://jira.atlassian.com/browse/JIRAALIGN-4326 • CWE-918: Server-Side Request Forgery (SSRF) •