Unauthorized Role Escalation in Atlassian Jira Align Server
CVE-2022-36803

8.8HIGH

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
14 October 2022

Summary

The MasterUserEdit API in Atlassian Jira Align Server versions before 10.109.2 is vulnerable to unauthorized role escalation. An authenticated attacker possessing the People role permission can exploit this API to elevate any user's role to that of a Super Admin. This flaw poses significant risks to system integrity and data security, allowing malicious users to gain unrestricted administrative access.

Affected Version(s)

Jira Align < 10.109.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.