Description
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.20.10, from version 8.21.0 before 8.22.4. This also affects Jira Management Server and Data Center versions from version 4.0.0 before 4.13.22, from version 4.14.0 before 4.20.10 and from version 4.21.0 before 4.22.4.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- Atlassian / Jira Core Server8.0.0 β unspecified
- Atlassian / Jira Core Serverunspecified β 8.13.22
- Atlassian / Jira Core Server8.14.0 β unspecified
- Atlassian / Jira Core Serverunspecified β 8.20.10
- Atlassian / Jira Core Server8.21.0 β unspecified
- Atlassian / Jira Core Serverunspecified β 8.22.4
- Atlassian / Jira Service Management Data Centerunspecified β 4.22.4
- Atlassian / Jira Service Management Data Center4.0.0 β unspecified
- Atlassian / Jira Service Management Data Centerunspecified β 4.13.22
- Atlassian / Jira Service Management Data Center4.14.0 β unspecified
- Atlassian / Jira Service Management Data Centerunspecified β 4.20.10
- Atlassian / Jira Service Management Data Center4.21.0 β unspecified
- Atlassian / Jira Service Management Server4.0.0 β unspecified
- Atlassian / Jira Service Management Serverunspecified β 4.13.22
- Atlassian / Jira Service Management Server4.14.0 β unspecified
- Atlassian / Jira Service Management Serverunspecified β 4.20.10
- Atlassian / Jira Service Management Server4.21.0 β unspecified
- Atlassian / Jira Service Management Serverunspecified β 4.22.4
- Atlassian / Jira Software Data Center8.0.0 β unspecified
- Atlassian / Jira Software Data Centerunspecified β 8.13.22
- Atlassian / Jira Software Data Center8.14.0 β unspecified
- Atlassian / Jira Software Data Centerunspecified β 8.20.10
- Atlassian / Jira Software Data Center8.21.0 β unspecified
- Atlassian / Jira Software Data Centerunspecified β 8.22.4
- Atlassian / Jira Software Server8.0.0 β unspecified
- Atlassian / Jira Software Serverunspecified β 8.13.22
- Atlassian / Jira Software Server8.14.0 β unspecified
- Atlassian / Jira Software Serverunspecified β 8.20.10
- Atlassian / Jira Software Server8.21.0 β unspecified
- Atlassian / Jira Software Serverunspecified β 8.22.4