The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator.
References
Link | Resource |
---|---|
https://ecosystem.atlassian.net/browse/UPM-6044 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-08-23 07:15
Updated : 2019-08-30 06:51
NVD link : CVE-2019-14999
Mitre link : CVE-2019-14999
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
atlassian
- universal_plugin_manager