The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator.
References
Link | Resource |
---|---|
https://ecosystem.atlassian.net/browse/UPM-6044 | Issue Tracking Vendor Advisory |
https://ecosystem.atlassian.net/browse/UPM-6044 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:27
Type | Values Removed | Values Added |
---|---|---|
References | () https://ecosystem.atlassian.net/browse/UPM-6044 - Issue Tracking, Vendor Advisory |
Information
Published : 2019-08-23 14:15
Updated : 2024-11-21 04:27
NVD link : CVE-2019-14999
Mitre link : CVE-2019-14999
CVE.ORG link : CVE-2019-14999
JSON object : View
Products Affected
atlassian
- universal_plugin_manager
CWE
CWE-352
Cross-Site Request Forgery (CSRF)