SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-26135

A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint.

MEDIUM 6.5EPSS 71.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 71.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.20.10, from version 8.21.0 before 8.22.4. This also affects Jira Management Server and Data Center versions from version 4.0.0 before 4.13.22, from version 4.14.0 before 4.20.10 and from version 4.21.0 before 4.22.4.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
71.17% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-918
Affected
atlassian/jira data center · atlassian/jira server · atlassian/jira service desk · atlassian/jira service management
Source
security@atlassian.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.