Unauthorized Role Escalation in Atlassian Jira Align Server
CVE-2022-36803
8.8HIGH
What is CVE-2022-36803?
The MasterUserEdit API in Atlassian Jira Align Server versions before 10.109.2 is vulnerable to unauthorized role escalation. An authenticated attacker possessing the People role permission can exploit this API to elevate any user's role to that of a Super Admin. This flaw poses significant risks to system integrity and data security, allowing malicious users to gain unrestricted administrative access.
Affected Version(s)
Jira Align < 10.109.2