Path traversal in Jira Software Data Center and Jira Software Server - CVE-2025-22167

 

Path traversal in Jira Software Data Center and Jira Software Server - CVE-2025-22167

Published: October 21, 2025 / Updated: October 31, 2025


Vulnerability identifier: #VU117434
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-22167
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote user can send a specially crafted HTTP request and write arbitrary files to the system, leading to remote code execution.


Affected software

Jira Software Data Center
Jira Service Management Data Center
Jira Service Management Server
Jira Software Server

How to mitigate CVE-2025-22167

Install updates from vendor's website.

Jira Software Data Center - addressed in versions 9.12.28, 10.3.12, 11.1.0
Jira Software Server - addressed in versions 9.12.28, 10.3.12, 11.1.0
Jira Service Management Data Center - addressed in versions 5.12.28, 10.3.12, 11.1.0
Jira Service Management Server - addressed in versions 5.12.28, 10.3.12, 11.1.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins