CVE-2025-22178: Medium severity Atlassian Jira Align vulnerability
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22178?
CVE-2025-22178 is classified as a low-severity vulnerability due to the limited amount of sensitive information that can be accessed by low-privilege users.
How do I fix CVE-2025-22178?
To fix CVE-2025-22178, review and update permission settings for endpoint access in Jira Align to restrict unauthorized data exposure.
Which versions of Atlassian Jira Align are affected by CVE-2025-22178?
All versions of Atlassian Jira Align prior to the fix are potentially affected by CVE-2025-22178.
What kind of information can a low-privilege user access due to CVE-2025-22178?
A low-privilege user may access unexpected endpoints that could expose a small amount of sensitive information, such as items on the 'Why' page.
Is there a workaround for CVE-2025-22178 while a fix is being implemented?
As a temporary workaround for CVE-2025-22178, consider tightening user role permissions to limit access to sensitive endpoints.