CVE-2022-36803 is a high-severity vulnerability affecting Atlassian Jira Align Server versions prior to 10.109.2. An authenticated attacker with "People" role permissions can exploit the MasterUserEdit API to elevate any user's role to Super Admin. This allows for complete compromise of confidentiality, integrity, and availability, as indicated by its CVSS score of 8.8. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.109.2CPE match | cpe:2.3:a:atlassian:jira_align:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.