Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1 allow remote attackers who have obtained access to administrator's session to access certain administrative resources without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Atlassian Jira | — | Upgrade to Atlassian JIRA version 7.10.3Upgrade to Atlassian JIRA version 7.7.5Upgrade to Atlassian JIRA version 7.12.3Upgrade to Atlassian JIRA version 7.13.1Upgrade to Atlassian JIRA version 7.8.5Upgrade to Atlassian JIRA version 7.9.3Upgrade to Atlassian JIRA version 7.6.9Upgrade to Atlassian JIRA version 7.11.3 | Jul 15, 2019 | Oct 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub