CVE-2022-36800: Medium severity atlassian jira service desk vulnerability
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version 4.22.2.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-36800.
What is the severity of CVE-2022-36800?
The severity of CVE-2022-36800 is medium with a CVSS score of 4.3.
How does CVE-2022-36800 impact Atlassian Jira Service Management?
CVE-2022-36800 allows remote attackers without the "Browse Users" permission to view groups, leading to an information disclosure vulnerability.
Which versions of Atlassian Jira Service Management are affected by CVE-2022-36800?
The affected versions of Atlassian Jira Service Management are before version 4.22.2 for both the Server and Data Center editions.
How can CVE-2022-36800 be fixed?
To fix CVE-2022-36800, it is recommended to upgrade Atlassian Jira Service Management to version 4.22.2 or later.