CVE-2025-22175: Medium severity Atlassian Jira Align vulnerability
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22175?
The severity of CVE-2025-22175 is classified as low.
How do I fix CVE-2025-22175?
To fix CVE-2025-22175, ensure that proper authorization checks are in place for user access to all endpoints.
What type of information can be accessed due to CVE-2025-22175?
CVE-2025-22175 allows low-privilege users to access unexpected endpoints that may reveal a small amount of sensitive information.
Which software versions are affected by CVE-2025-22175?
Atlassian Jira Align is affected by CVE-2025-22175, though specific version details were not provided.
Who is primarily impacted by CVE-2025-22175?
Low-privilege users of Jira Align are primarily impacted by CVE-2025-22175 as it allows them unauthorized access to certain functionalities.