Description
The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check.
Remediation
References
Related Vulnerabilities
WordPress Plugin Newsletters Multiple Vulnerabilities (4.6.14)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-7128)
WordPress Plugin File Manager Unspecified Vulnerability (5.1.5)
Oracle JRE Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3174)