CVE-2007-6619Atlassian Jira vulnerability

CWE-2643 documents3 sources
Severity
7.5HIGHNVD
EPSS
0.6%
top 30.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 3
Latest updateMay 1

Description

The Setup Wizard in Atlassian JIRA Enterprise Edition before 3.12.1 does not properly restrict setup attempts after setup is complete, which allows remote attackers to change the default language.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDatlassian/jira3.12

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qc68-5gff-qw5c: The Setup Wizard in Atlassian JIRA Enterprise Edition before 32022-05-01
CVEList
CVE-2007-6619: The Setup Wizard in Atlassian JIRA Enterprise Edition before 32008-01-03
CVE-2007-6619 — Atlassian Jira vulnerability | cvebase