CVE-2019-15013
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to remove a configured issue status from a project via a missing authorisation check.
El método removeStatus de la clase WorkflowResource en Jira versiones anteriores a la versión 7.13.12, desde la versión 8.0.0 anteriores a la versión 8.4.3 y desde la versión 8.5.0 anteriores a la versión 8.5.2, permite a atacantes remotos autenticados que no tienen acceso de administración del proyecto eliminar un estado del problema configurado desde el proyecto por medio de una falta de comprobación de autorización.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-08-13 CVE Reserved
- 2019-12-18 CVE Published
- 2023-03-07 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://jira.atlassian.com/browse/JRASERVER-70405 | 2022-03-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Atlassian Search vendor "Atlassian" | Jira Search vendor "Atlassian" for product "Jira" | < 7.13.12 Search vendor "Atlassian" for product "Jira" and version " < 7.13.12" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Jira Server Search vendor "Atlassian" for product "Jira Server" | >= 8.0.0 < 8.4.3 Search vendor "Atlassian" for product "Jira Server" and version " >= 8.0.0 < 8.4.3" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Jira Server Search vendor "Atlassian" for product "Jira Server" | >= 8.5.0 < 8.5.2 Search vendor "Atlassian" for product "Jira Server" and version " >= 8.5.0 < 8.5.2" | - |
Affected
|