VulnerabilityModified
CVE-2022-38367
This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint.
MEDIUM 5.3EPSS 0.49%
Does this matter?
Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.
Description
The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.49% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- netic/user export for jira
- Source
- cve@mitre.org
References
- https://gist.github.com/CveCt0r/72a0b6292cd8d80499cf5971ae58147fThird Party Advisory
- https://marketplace.atlassian.com/apps/1220535/user-export-for-jiraProduct, Vendor Advisory
- https://gist.github.com/CveCt0r/72a0b6292cd8d80499cf5971ae58147fThird Party Advisory
- https://marketplace.atlassian.com/apps/1220535/user-export-for-jiraProduct, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.