Aller au contenu

Fiche vulnérabilité

CVE-2022-36803 : faille élevée atlassian jira align (CVSS 8.8)

Description

The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
14 oct. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • atlassian jira align

Références

Rechercher une autre vulnérabilité dans la base CVE