← Back

CVE-2022-26135

nvd nist
Published: Jun 30, 2022Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.20.10, from version 8.21.0 before 8.22.4. This also affects Jira Management Server and Data Center versions from version 4.0.0 before 4.13.22, from version 4.14.0 before 4.20.10 and from version 4.21.0 before 4.22.4.

Affected (12)

4 products
Jira Data Center
Jira Server
Jira Service Desk
Jira Service Management
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Atlassian
From 8.0.0 to 8.13.22
From 8.14.0 to 8.20.10
From 8.21.0 to 8.22.4
Atlassian
From 8.0.0 to 8.13.22
From 8.14.0 to 8.20.10
From 8.21.0 to 8.22.4
Atlassian
From 4.0.0 to 4.13.22
From 4.0.0 to 4.13.22
Atlassian
From 4.14.0 to 4.20.10
From 4.21.0 to 4.22.4
From 4.14.0 to 4.20.10
From 4.21.0 to 4.22.4

References (6)

Source: security@atlassian.com
Vendor Advisory
Source: security@atlassian.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.