PT-2022-5139 · Atlassian+5 · Jira Work Management+7

Published

2022-10-04

·

Updated

2026-05-18

·

CVE-2022-3171

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions protobuf-java versions prior to 3.21.7 protobuf-java versions prior to 3.20.3 protobuf-java versions prior to 3.19.6 protobuf-java versions prior to 3.16.3 Jira Service Management (affected versions not specified) Jira Work Management (affected versions not specified)
Description The issue is related to insufficient input validation in the Java Protocol Buffers library, which can lead to a denial of service attack. A parsing problem with binary data in protobuf-java can cause objects to be converted back and forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. This can occur when inputs contain multiple instances of non-repeated embedded messages with repeated or unknown fields.
Recommendations For protobuf-java versions prior to 3.21.7, update to version 3.21.7 or later. For protobuf-java versions prior to 3.20.3, update to version 3.20.3 or later. For protobuf-java versions prior to 3.19.6, update to version 3.19.6 or later. For protobuf-java versions prior to 3.16.3, update to version 3.16.3 or later. For Jira Service Management, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Jira Work Management, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1230
BDU:2022-06396
CLEANSTART-2026-DD05788
CLEANSTART-2026-JU62349
CLEANSTART-2026-KU61465
CLEANSTART-2026-LE11246
CLEANSTART-2026-RN56220
CLEANSTART-2026-SQ91016
CLEANSTART-2026-SV95049
CLEANSTART-2026-VH41554
CLEANSTART-2026-WK99982
CVE-2022-3171
GHSA-H4H5-3HR4-J3G2
MGASA-2023-0092
OESA-2022-2010
OESA-2022-2011
OESA-2022-2012
OPENSUSE-SU-2022_3922-1
SUSE-SU-2022:3922-1
SUSE-SU-2023:2783-1
SUSE-SU-2023:2783-2

Affected Products

Alt Linux
Debian
Jira
Jira Service Management Server
Jira Work Management
Red Os
Suse
Protobuf-Java