« Volver al listado

CVE-2025-22157

Estado: AnalizadaAlta (7.2)—

This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions:

9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server

5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center and Server

This PrivEsc (Privilege Escalation) vulnerability, with a CVSS Score of 7.2, allows an attacker to perform actions as a higher-privileged user.

Atlassian recommends that Jira Core Data Center and Server and Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:

Leer descripción completaMostrar menos

Jira Core Data Center and Server 9.12: Upgrade to a release greater than or equal to 9.12.20

Jira Service Management Data Center and Server 5.12: Upgrade to a release greater than or equal to 5.12.20

Jira Core Data Center 10.3: Upgrade to a release greater than or equal to 10.3.5

Jira Service Management Data Center 10.3: Upgrade to a release greater than or equal to 10.3.5

Jira Core Data Center 10.4: Upgrade to a release greater than or equal to 10.6.0

Jira Service Management Data Center 10.4: Upgrade to a release greater than or equal to 10.6.0

Jira Core Data Center 10.5: Upgrade to a release greater than or equal to 10.5.1

Jira Service Management Data Center 10.5: Upgrade to a release greater than or equal to 10.5.1

See the release notes. You can download the latest version of Jira Core Data Center and Jira Service Management Data Center from the download center.

This vulnerability was reported via our Atlassian (Internal) program.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de escalada de privilegios en Jira (PR:L, red) que permite a un atacante autenticado ejecutar acciones como usuario de mayor privilegio. VI:H y VA:H confirman impactos en integridad y disponibilidad mediante elevación de permisos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-22157",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-22157",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-21T03:55:33.263670Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "security@atlassian.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 7.2,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "security@atlassian.com",
      "affectedData": [
        {
          "vendor": "Atlassian",
          "product": "Jira Core Data Center",
          "versions": [
            {
              "status": "affected",
              "version": "10.5.0"
            },
            {
              "status": "affected",
              "version": "10.4.0 to 10.4.1"
            },
            {
              "status": "affected",
              "version": "10.3.0 to 10.3.4"
            },
            {
              "status": "affected",
              "version": "9.12.0 to 9.12.19"
            },
            {
              "status": "unaffected",
              "version": "10.6.0"
            },
            {
              "status": "unaffected",
              "version": "10.5.1"
            },
            {
              "status": "unaffected",
              "version": "10.3.5 to 10.3.6"
            },
            {
              "status": "unaffected",
              "version": "9.12.22 to 9.12.23"
            }
          ]
        },
        {
          "vendor": "Atlassian",
          "product": "Jira Core Server",
          "versions": [
            {
              "status": "affected",
              "version": "9.12.0 to 9.12.19"
            },
            {
              "status": "unaffected",
              "version": "9.12.22 to 9.12.23"
            }
          ]
        },
        {
          "vendor": "Atlassian",
          "product": "Jira Service Management Data Center",
          "versions": [
            {
              "status": "affected",
              "version": "10.5.0"
            },
            {
              "status": "affected",
              "version": "10.4.0 to 10.4.1"
            },
            {
              "status": "affected",
              "version": "10.3.0 to 10.3.4"
            },
            {
              "status": "affected",
              "version": "5.12.0 to 5.12.19"
            },
            {
              "status": "unaffected",
              "version": "10.6.0"
            },
            {
              "status": "unaffected",
              "version": "10.5.1"
            },
            {
              "status": "unaffected",
              "version": "10.3.5 to 10.3.6"
            },
            {
              "status": "unaffected",
              "version": "5.12.22 to 5.12.23"
            }
          ]
        },
        {
          "vendor": "Atlassian",
          "product": "Jira Service Management Server",
          "versions": [
            {
              "status": "affected",
              "version": "5.12.0 to 5.12.19"
            },
            {
              "status": "unaffected",
              "version": "5.12.22 to 5.12.23"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-05-20T18:15:44.990",
  "references": [
    {
      "url": "https://confluence.atlassian.com/pages/viewpage.action?pageId=1561365992",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@atlassian.com"
    },
    {
      "url": "https://jira.atlassian.com/browse/JRASERVER-78766",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@atlassian.com"
    },
    {
      "url": "https://jira.atlassian.com/browse/JSDSERVER-16206",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@atlassian.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions:\n\n9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server\n\n5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center and Server\n\nThis PrivEsc (Privilege Escalation) vulnerability, with a CVSS Score of 7.2, allows an attacker to perform actions as a higher-privileged user. \n\nAtlassian recommends that Jira Core Data Center and Server and Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\nJira Core Data Center and Server 9.12: Upgrade to a release greater than or equal to 9.12.20\n\nJira Service Management Data Center and Server 5.12: Upgrade to a release greater than or equal to 5.12.20\n\nJira Core Data Center 10.3: Upgrade to a release greater than or equal to 10.3.5\n\nJira Service Management Data Center 10.3: Upgrade to a release greater than or equal to 10.3.5\n\nJira Core Data Center 10.4: Upgrade to a release greater than or equal to 10.6.0\n\nJira Service Management Data Center 10.4: Upgrade to a release greater than or equal to 10.6.0\n\nJira Core Data Center 10.5: Upgrade to a release greater than or equal to 10.5.1\n\nJira Service Management Data Center 10.5: Upgrade to a release greater than or equal to 10.5.1\n\nSee the release notes. You can download the latest version of Jira Core Data Center and Jira Service Management Data Center from the download center. \n\nThis vulnerability was reported via our Atlassian (Internal) program."
    },
    {
      "lang": "es",
      "value": "Esta vulnerabilidad PrivEsc (escalada de privilegios) de alta gravedad se introdujo en las versiones: 9.12.0, 10.3.0, 10.4.0 y 10.5.0 de Jira Core Data Center y Server 5.12.0, 10.3.0, 10.4.0 y 10.5.0 de Jira Service Management Data Center y Server Esta vulnerabilidad PrivEsc (escalada de privilegios), con un puntaje CVSS de 7.2, permite a un atacante realizar acciones como un usuario con mayores privilegios. Atlassian recomienda que los clientes de Jira Core Data Center and Server y Jira Service Management Data Center and Server actualicen a la última versión. Si no pueden hacerlo, actualicen su instancia a una de las versiones fijas compatibles especificadas: Jira Core Data Center and Server 9.12: Actualizar a una versión posterior o igual a la 9.12.20 Jira Service Management Data Center and Server 5.12: Actualizar a una versión posterior o igual a la 5.12.20 Jira Core Data Center 10.3: Actualizar a una versión posterior o igual a la 10.3.5 Jira Service Management Data Center 10.3: Actualizar a una versión posterior o igual a la 10.3.5 Jira Core Data Center 10.4: Actualizar a una versión posterior o igual a la 10.6.0 Jira Service Management Data Center 10.4: Actualizar a una versión posterior o igual a la 10.6.0 Jira Core Data Center 10.5: Actualizar a una versión posterior o igual a la 10.5.1 Jira Service Management Data Center 10.5: Actualice a una versión superior o igual a la 10.5.1. Consulte las notas de la versión. Puede descargar la última versión de Jira Core Data Center y Jira Service Management Data Center desde el centro de descargas. Esta vulnerabilidad se reportó a través de nuestro programa interno de Atlassian."
    }
  ],
  "lastModified": "2026-06-17T08:45:24.510",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A58188C-A256-4B44-BE7A-EDF08AD53F26",
              "versionEndExcluding": "5.12.20",
              "versionStartIncluding": "5.12.0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DED58CA4-3F2E-4403-B50F-4A9BF4F7E56A",
              "versionEndExcluding": "9.12.20",
              "versionStartIncluding": "9.12.0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "911B9E77-9F74-4FAC-AE3A-94796627B892",
              "versionEndExcluding": "10.3.5",
              "versionStartIncluding": "10.3.0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8E2CCC8-3188-4700-BA60-BC9B46AB3E46",
              "versionEndExcluding": "10.5.1",
              "versionStartIncluding": "10.4.0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B97FDE83-AAC2-4A70-AD9F-CB3033EED42E",
              "versionEndExcluding": "9.12.20",
              "versionStartIncluding": "9.12.0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE2214F4-055F-4F6C-B80E-59D2D786D9D1",
              "versionEndExcluding": "10.3.5",
              "versionStartIncluding": "10.3.0"
            },
            {
              "criteria": "cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C4EADC6-848E-4135-AAA2-88074945F89B",
              "versionEndExcluding": "10.5.1",
              "versionStartIncluding": "10.4.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@atlassian.com"
}