CVE-2019-8443

HIGH

Jira < 7.13.4, 8.0.0-8.0.4, 8.1.0-8.1.1 - Improper Authentication via ViewUpgrades Resource

Title source: llm
STIX 2.1

Description

The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability.

References (2)

Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-69240
Broken Link vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108458

Scores

CVSS v3 8.1
EPSS 0.0057
EPSS Percentile 68.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (2)
atlassian/jira < 7.13.4
atlassian/jira_server 8.0.0 - 8.0.4
Published May 22, 2019
Tracked Since Feb 18, 2026