CVE-2025-22168: Medium severity Atlassian Jira Align vulnerability
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22168?
CVE-2025-22168 has a low severity rating due to the limited amount of sensitive information exposed.
How do I fix CVE-2025-22168?
To mitigate CVE-2025-22168, ensure that users have the correct permissions and consider applying any available patches from Atlassian.
What types of sensitive information are impacted by CVE-2025-22168?
CVE-2025-22168 allows unauthorized access to private checklists, potentially revealing task steps of other users.
What versions of Jira Align are affected by CVE-2025-22168?
All versions of Atlassian Jira Align are vulnerable to CVE-2025-22168 as there is no specific version listed as exempt.
Is there a workaround for CVE-2025-22168?
A potential workaround for CVE-2025-22168 includes reviewing and adjusting user permissions to restrict access to sensitive endpoints.