CVE-2025-22172: Medium severity Atlassian Jira Align vulnerability
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22172?
CVE-2025-22172 has a low severity rating due to the limited access to minor sensitive information.
How do I fix CVE-2025-22172?
To fix CVE-2025-22172, ensure that access controls are properly configured to restrict low-privilege users from accessing sensitive endpoints.
What is the impact of CVE-2025-22172?
The impact of CVE-2025-22172 allows low-privilege users to view external reports that they should not have permission to access.
Who is affected by CVE-2025-22172?
CVE-2025-22172 affects users of Atlassian Jira Align, particularly low-privilege roles within the system.
What product is vulnerable to CVE-2025-22172?
Atlassian Jira Align is the product that is vulnerable to CVE-2025-22172 due to an authorization issue.