#VU21327 Improper access control in Jira Software - CVE-2019-8443
Published: September 25, 2019
Jira Software
Atlassian
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the "ViewUpgrades" resource. A remote attacker who have obtained access to administrator's session can bypass implemented security restrictions and gain unauthorized access to the "ViewUpgrades" administrative resource without needing to re-authenticate to pass "WebSudo".