Show plain JSON{"id": "CVE-2019-15013", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N", "authentication": "SINGLE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 4.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "NONE"}, "impactScore": 1.4, "exploitabilityScore": 2.8}]}, "published": "2019-12-18T04:15:14.197", "references": [{"url": "https://jira.atlassian.com/browse/JRASERVER-70405", "tags": ["Vendor Advisory"], "source": "security@atlassian.com"}, {"url": "https://jira.atlassian.com/browse/JRASERVER-70405", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-862"}]}], "descriptions": [{"lang": "en", "value": "The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to remove a configured issue status from a project via a missing authorisation check."}, {"lang": "es", "value": "El m\u00e9todo removeStatus de la clase WorkflowResource en Jira versiones anteriores a la versi\u00f3n 7.13.12, desde la versi\u00f3n 8.0.0 anteriores a la versi\u00f3n 8.4.3 y desde la versi\u00f3n 8.5.0 anteriores a la versi\u00f3n 8.5.2, permite a atacantes remotos autenticados que no tienen acceso de administraci\u00f3n del proyecto eliminar un estado del problema configurado desde el proyecto por medio de una falta de comprobaci\u00f3n de autorizaci\u00f3n."}], "lastModified": "2024-11-21T04:27:52.437", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F460A680-2B63-426A-8A84-4C82FBF1F9CC", "versionEndExcluding": "7.13.12"}, {"criteria": "cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B693DA20-3CDC-4089-82E3-F169BDFC3B04", "versionEndExcluding": "8.4.3", "versionStartIncluding": "8.0.0"}, {"criteria": "cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "092C476C-0D3A-41A1-90E3-295730FD74EB", "versionEndExcluding": "8.5.2", "versionStartIncluding": "8.5.0"}], "operator": "OR"}]}], "sourceIdentifier": "security@atlassian.com"}