CVE-2019-15013

MEDIUM

Jira < 7.13.12, 8.0.0-8.4.3, 8.5.0-8.5.2 - Authenticated Missing Authorization in WorkflowResource

Title source: llm
STIX 2.1

Description

The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to remove a configured issue status from a project via a missing authorisation check.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-70405

Scores

CVSS v3 4.3
EPSS 0.0025
EPSS Percentile 48.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-862
Status published
Products (2)
atlassian/jira < 7.13.12
atlassian/jira_server 8.0.0 - 8.4.3
Published Dec 18, 2019
Tracked Since Feb 18, 2026