CVE Database
/

CVE-2022-26135

Back to search

CVE-2022-26135

Published: Jun 30, 2022

Modified: Oct 29, 2024

PUBLISHED

Description

A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.20.10, from version 8.21.0 before 8.22.4. This also affects Jira Management Server and Data Center versions from version 4.0.0 before 4.13.22, from version 4.14.0 before 4.20.10 and from version 4.21.0 before 4.22.4.

VendorProductVersions

Atlassian

Jira Core Server

affected
8.0.0 - < unspecified
affected
unspecified - < 8.13.22
affected
8.14.0 - < unspecified
affected
unspecified - < 8.20.10
affected
8.21.0 - < unspecified

+1 more versions

Atlassian

Jira Software Server

affected
8.0.0 - < unspecified
affected
unspecified - < 8.13.22
affected
8.14.0 - < unspecified
affected
unspecified - < 8.20.10
affected
8.21.0 - < unspecified

+1 more versions

Atlassian

Jira Software Data Center

affected
8.0.0 - < unspecified
affected
unspecified - < 8.13.22
affected
8.14.0 - < unspecified
affected
unspecified - < 8.20.10
affected
8.21.0 - < unspecified

+1 more versions

Atlassian

Jira Service Management Server

affected
4.0.0 - < unspecified
affected
unspecified - < 4.13.22
affected
4.14.0 - < unspecified
affected
unspecified - < 4.20.10
affected
4.21.0 - < unspecified

+1 more versions

Atlassian

Jira Service Management Data Center

affected
4.0.0 - < unspecified
affected
unspecified - < 4.13.22
affected
4.14.0 - < unspecified
affected
unspecified - < 4.20.10
affected
4.21.0 - < unspecified

+1 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now