Insufficient verification of data authenticity in Atlassian products - CVE-2022-26137

 

Insufficient verification of data authenticity in Atlassian products - CVE-2022-26137

Published: July 29, 2022


Vulnerability identifier: #VU65892
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26137
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to origin validation error when processing HTTP requests, related to cross-origin sharing (CORS) in the Servlet Filter. A remote attacker can trick the victim to follow a specially crafted link and access the vulnerable application with the victim’s permissions.


Affected software

Crowd Data Center
Crucible Server
Jira Service Management Server
Bamboo Server
Confluence Data Center
Bitbucket Data Center
Atlassian Fisheye
Jira Software Server

How to mitigate CVE-2022-26137

Install update from vendor's website.

Crowd Data Center - addressed in versions 4.3.8, 4.4.2, 5.0.1
Atlassian Fisheye - update to 4.8.10
Crucible Server - update to 4.8.10
Jira Service Management Server - addressed in versions 4.13.22, 4.20.10, 4.22.4, 4.22.6, 5.0.0
Bamboo Server - addressed in versions 7.2.10, 8.0.9, 8.1.8, 8.2.4, 9.0.0
Confluence Data Center - addressed in versions 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, 7.18.1
Bitbucket Data Center - addressed in versions 7.6.16, 7.17.8, 7.19.5, 7.20.2, 8.0.1, 8.1.1, 8.2.0
Jira Software Server - addressed in versions 8.13.22, 8.20.10, 8.22.6, 9.0.0

External References

Related Security Bulletins