Atlassian
Atlassian Jira Align: vulnerabilidades y CVE
Atlassian Jira Align tiene 13 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses11
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-22178 | Media (5.3) | 0.21% | — | 22 oct 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the… |
| CVE-2025-22177 | Media (5.3) | 0.21% | — | 22 oct 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team… |
| CVE-2025-22176 | Media (5.3) | 0.21% | — | 22 oct 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log… |
| CVE-2025-22175 | Media (5.3) | 0.18% | — | 22 oct 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps… |
| CVE-2025-22174 | Media (5.3) | 0.21% | — | 22 oct 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio… |
| CVE-2025-22173 | Media (5.3) | 0.21% | — | 22 oct 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain… |
| CVE-2025-22172 | Media (5.3) | 0.21% | — | 22 oct 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external… |
| CVE-2025-22171 | Media (5.3) | 0.19% | — | 22 oct 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users. |
| CVE-2025-22170 | Media (5.3) | 0.21% | — | 22 oct 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient… |
| CVE-2025-22169 | Media (5.3) | 0.18% | — | 22 oct 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an… |
| CVE-2025-22168 | Media (5.3) | 0.21% | — | 22 oct 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of… |
| CVE-2022-36803 | Alta (8.8) | 0.60% | — | 14 oct 2022 | The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This… |
| CVE-2022-36802 | Media (4.9) | 0.91% | — | 14 oct 2022 | The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery. This can be exploited by… |