Unauthorized Role Escalation in Atlassian Jira Align Server
CVE-2022-36803
8.8HIGH
Summary
The MasterUserEdit API in Atlassian Jira Align Server versions before 10.109.2 is vulnerable to unauthorized role escalation. An authenticated attacker possessing the People role permission can exploit this API to elevate any user's role to that of a Super Admin. This flaw poses significant risks to system integrity and data security, allowing malicious users to gain unrestricted administrative access.
Affected Version(s)
Jira Align < 10.109.2
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved