Description
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin FormGet Contact Form Cross-Site Scripting (5.3)
WordPress Plugin eCommerce Product Catalog for WordPress Cross-Site Scripting (3.0.38)
Oracle Database Server CVE-2008-0346 Vulnerability (CVE-2008-0346)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2006-0553)