CVE-2019-8443: High severity atlassian jira vulnerability
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8443?
CVE-2019-8443 is considered a medium severity vulnerability that allows unauthorized access to sensitive administrative resources in Jira.
How do I fix CVE-2019-8443?
To fix CVE-2019-8443, upgrade Jira to version 7.13.4 or to versions 8.0.4 or 8.1.1 or later.
Who is affected by CVE-2019-8443?
CVE-2019-8443 affects versions of Jira prior to 7.13.4, those between 8.0.0 and 8.0.4, and 8.1.0 to 8.1.1.
What type of attack does CVE-2019-8443 enable?
CVE-2019-8443 enables remote attackers with access to an administrator's session to exploit the ViewUpgrades resource.
What are the consequences of CVE-2019-8443?
The consequences of CVE-2019-8443 include potential unauthorized access to Jira administrative functions that could lead to system compromise.