Loading HuntDB...

GHSA-3w8c-ghf8-rmwq

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator.

Related CVEs

Key Information

GHSA ID
GHSA-3w8c-ghf8-rmwq
Published
May 24, 2022 4:54 PM
Last Modified
April 4, 2024 1:46 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.