Description
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin Subscribe to Comments Unsubscribe Challenge Information Disclosure (2.0.2)
WordPress Plugin Zoho CRM Lead Magnet Unspecified Vulnerability (1.7.2.9)
WordPress Plugin Onclick show popup Cross-Site Scripting (6.5)
Ruby on Rails Missing Encryption of Sensitive Data Vulnerability (CVE-2010-3299)