Description
Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscriptions via a Broken Access Control vulnerability in the /secure/EditSubscription.jspa endpoint. The affected versions are before version 8.21.0.
Remediation
References
Related Vulnerabilities
PostgreSQL Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2005-0227)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-0866)
WordPress Plugin WooCommerce Product Table Lite Cross-Site Scripting (2.3.0)
MySQL Use of Externally-Controlled Format String Vulnerability (CVE-2008-3963)