Improper Authentication in Atlassian products - CVE-2022-0540
Published: April 25, 2022 / Updated: May 26, 2022
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in the Jira Seraph. A remote attacker can send a specially crafted HTTP request to bypass authentication and authorization requirements in WebWork actions and gain unauthorized access to the application.
The vulnerability affects applications that specify roles-required at the webwork1 action namespace level and do not specify it at an action level.
Affected software
Jira Service Management Data Center
Jira Software Data Center
Jira Software Server
How to mitigate CVE-2022-0540
Jira Service Management Data Center - addressed in versions 4.13.18, 4.20.6, 4.22.0
Jira Software Data Center - addressed in versions 8.13.18, 8.20.6, 8.22.0
Jira Software Server - addressed in versions 8.13.18, 8.20.6, 8.22.0