CVE-2025-22177: Medium severity Atlassian Jira Align vulnerability
Published Oct 22, 2025
·Updated
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.
Affected Software
2 affected components
Atlassian Jira Align
Atlassian Jira Align>=11.14.0<11.16.1
Event History
Oct 22, 2025
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22177?
CVE-2025-22177 is classified as a low-severity vulnerability.
2
How do I fix CVE-2025-22177?
To fix CVE-2025-22177, ensure that user permissions are properly configured to restrict access to sensitive endpoints.
3
Who is affected by CVE-2025-22177?
Low-privilege users of Atlassian Jira Align are affected by CVE-2025-22177.
4
What type of information can be accessed via CVE-2025-22177?
CVE-2025-22177 allows low-privilege users to view unexpected endpoints revealing a small amount of sensitive information.
5
What versions of Atlassian Jira Align are vulnerable to CVE-2025-22177?
All versions of Atlassian Jira Align are considered vulnerable to CVE-2025-22177.