Improper Authentication in Atlassian products - CVE-2022-0540

 

Improper Authentication in Atlassian products - CVE-2022-0540

Published: April 25, 2022 / Updated: May 26, 2022


Vulnerability identifier: #VU62540
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0540
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in the Jira Seraph. A remote attacker can send a specially crafted HTTP request to bypass authentication and authorization requirements in WebWork actions and gain unauthorized access to the application.

The vulnerability affects applications that specify roles-required at the webwork1 action namespace level and do not specify it at an action level.


Affected software

Jira Service Management Server
Jira Service Management Data Center
Jira Software Data Center
Jira Software Server

How to mitigate CVE-2022-0540

Install updates from vendor's website.

Jira Service Management Server - addressed in versions 4.13.18, 4.20.6, 4.22.0
Jira Service Management Data Center - addressed in versions 4.13.18, 4.20.6, 4.22.0
Jira Software Data Center - addressed in versions 8.13.18, 8.20.6, 8.22.0
Jira Software Server - addressed in versions 8.13.18, 8.20.6, 8.22.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins