CVE-2019-8443
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability.
El recurso ViewUpgrades en Jira antes de la versión 7.13.4, desde la versión 8.0.0 antes de la versión 8.0.4, y desde la versión 8.1.0 antes de la versión 8.1.1, permite a los atacantes remotos que han obtenido acceso a la sesión del administrador acceder al recurso administrativo de ViewUpgrades sin necesidad de volver a autenticarse para pasar "WebSudo" mediante una vulnerabilidad de Control de Acceso incorrecta.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-02-18 CVE Reserved
- 2019-05-22 CVE Published
- 2023-03-07 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/108458 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://jira.atlassian.com/browse/JRASERVER-69240 | 2022-04-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Atlassian Search vendor "Atlassian" | Jira Search vendor "Atlassian" for product "Jira" | < 7.13.4 Search vendor "Atlassian" for product "Jira" and version " < 7.13.4" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Jira Server Search vendor "Atlassian" for product "Jira Server" | >= 8.0.0 < 8.0.4 Search vendor "Atlassian" for product "Jira Server" and version " >= 8.0.0 < 8.0.4" | - |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Jira Server Search vendor "Atlassian" for product "Jira Server" | >= 8.1.0 < 8.1.1 Search vendor "Atlassian" for product "Jira Server" and version " >= 8.1.0 < 8.1.1" | - |
Affected
|