CVE-2019-14999

MEDIUM

Atlassian Universal Plugin Manager <2.22.19, 3.0.0-3.0.3, 4.0.0-4.0.3 CSRF via Uninstall REST Endpoint

Title source: llm
STIX 2.1

Description

The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://ecosystem.atlassian.net/browse/UPM-6044

Scores

CVSS v3 4.3
EPSS 0.0009
EPSS Percentile 24.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-352
Status published
Products (1)
atlassian/universal_plugin_manager < 2.22.19
Published Aug 23, 2019
Tracked Since Feb 18, 2026