CVE-2025-22170: Medium severity Atlassian Jira Align vulnerability
Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22170?
CVE-2025-22170 is classified as a low-severity authorization issue.
How do I fix CVE-2025-22170?
To fix CVE-2025-22170, ensure that the authorization checks are properly implemented for all actions in Jira Align.
Who is affected by CVE-2025-22170?
Low-privilege users in Jira Align are affected by CVE-2025-22170 when they attempt to exploit authorization flaws.
What action can a low-privilege user take to exploit CVE-2025-22170?
A low-privilege user could exploit CVE-2025-22170 by including a state-related parameter of a high-privilege user.
What version of Jira Align is impacted by CVE-2025-22170?
CVE-2025-22170 affects all versions of Atlassian Jira Align without specific version limitations.