QID 150643
Date Published: 2023-02-16
QID 150643: Atlassian Jira Server and Data Center Server-Side Request Forgery (SSRF) Vulnerability (CVE-2022-26135)
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
A full-read server-side request forgery exists in Mobile Plugin for Jira, which is bundled with Jira and Jira Service Management. It is exploitable by any authenticated user (including a user who joined via the sign-up feature). It specifically affects the batch HTTP endpoint used in Mobile Plugin for Jira.
Affected versions:
Versions after 8.0 and before 8.13.22
8.14.x
8.15.x
8.16.x
8.17.x
8.18.x
8.19.x
8.20.x before 8.20.10
8.21.x
8.22.x before 8.22.4
QID Detection Logic:(Unauthenticated):
This QID sends a HTTP GET request and checks for vulnerable version of Atlassian Jira Server.
Successful exploitation of this vulnerability could lead to a security breach or could affect confidentiality, integrity, and availability.
For more information please refer to Atlassian Jira Security Advisory.
- Atlassian Jira Security Advisory -
confluence.atlassian.com/jira/jira-server-security-advisory-29nd-june-2022-1142430667.html
CVEs related to QID 150643
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-73863 |
|