Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Jira | Atlassian | * | 8.6.0 (excluding) |
| Jira_software_data_center | Atlassian | * | 8.6.0 (excluding) |