PT-2022-6383 · Atlassian · Jira Service Management Server

Published

2022-07-22

·

Updated

2024-10-29

·

CVE-2022-36800

CVSS v2.0

6.1

Medium

VectorAV:N/AC:L/Au:M/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Atlassian Jira Service Management Server and Data Center versions prior to 4.22.2
Description The issue allows remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the "browsegroups.action" endpoint. This is related to insufficient request validation on the server side, which can be exploited to perform a Server-Side Request Forgery (SSRF) attack.
Recommendations For versions prior to 4.22.2, update to version 4.22.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "browsegroups.action" endpoint until a patch is available. Avoid using the endpoint without proper validation and authorization to minimize the risk of exploitation.

Fix

SSRF

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2023-01119
CVE-2022-36800

Affected Products

Jira Service Management Server