First published: Wed Aug 03 2022(Updated: )
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version 4.22.2.
Credit: security@atlassian.com security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Jira Service Management | <4.22.2 | |
Atlassian Jira Service Management | <4.22.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-36800.
The severity of CVE-2022-36800 is medium with a CVSS score of 4.3.
CVE-2022-36800 allows remote attackers without the "Browse Users" permission to view groups, leading to an information disclosure vulnerability.
The affected versions of Atlassian Jira Service Management are before version 4.22.2 for both the Server and Data Center editions.
To fix CVE-2022-36800, it is recommended to upgrade Atlassian Jira Service Management to version 4.22.2 or later.