CVE-2025-22174: Medium severity Atlassian Jira Align vulnerability
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22174?
CVE-2025-22174 has a low severity rating due to the limited amount of sensitive information disclosed.
How do I fix CVE-2025-22174?
To mitigate CVE-2025-22174, ensure proper authorization controls are in place to prevent low-privilege users from accessing restricted endpoints.
What type of vulnerability is CVE-2025-22174?
CVE-2025-22174 is an authorization issue that allows low-privilege users to access endpoints without proper permissions.
Who is affected by CVE-2025-22174?
Users of Atlassian Jira Align, particularly those with low-level privileges, are affected by CVE-2025-22174.
What information can low-privilege users access in CVE-2025-22174?
Low-privilege users can unexpectedly access portfolio rooms, which may reveal a small amount of sensitive information.