CVE-2022-26135
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 71.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.20.10, from version 8.21.0 before 8.22.4. This also affects Jira Management Server and Data Center versions from version 4.0.0 before 4.13.22, from version 4.14.0 before 4.20.10 and from version 4.21.0 before 4.22.4.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 71.17% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- atlassian/jira data center · atlassian/jira server · atlassian/jira service desk · atlassian/jira service management
- Source
- security@atlassian.com
References
- https://confluence.atlassian.com/display/JIRA/Jira+Server+Security+Advisory+29nd+June+2022Mitigation, Vendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-73863Vendor Advisory
- https://jira.atlassian.com/browse/JSDSERVER-11840Vendor Advisory
- https://confluence.atlassian.com/display/JIRA/Jira+Server+Security+Advisory+29nd+June+2022Mitigation, Vendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-73863Vendor Advisory
- https://jira.atlassian.com/browse/JSDSERVER-11840Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.