CVE-2025-22171: Medium severity Atlassian Jira Align vulnerability
Published Oct 22, 2025
·Updated
Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.
Affected Software
2 affected components
Atlassian Jira Align
Atlassian Jira Align>=11.14.0<11.16.1
Event History
Oct 22, 2025
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22171?
The severity of CVE-2025-22171 is classified as low due to it being an authorization issue affecting user privacy.
2
How do I fix CVE-2025-22171?
To fix CVE-2025-22171, update your Atlassian Jira Align to the latest version where the vulnerability is patched.
3
Who is affected by CVE-2025-22171?
Low-privilege users of Atlassian Jira Align can be affected by CVE-2025-22171 as they can alter the private checklists of other users.
4
What type of vulnerability is CVE-2025-22171?
CVE-2025-22171 is an authorization issue that allows unauthorized alterations to users' private data.
5
Can CVE-2025-22171 be exploited remotely?
Yes, CVE-2025-22171 can potentially be exploited remotely by low-privilege users within the Atlassian Jira Align system.