Atlassian Releases Security Updates for Jira and Jira Service Management products
Updates address critical vulnerability known as CVE-2022-0540, which has a CVSS score of 9.9
Summary
Updates address critical vulnerability known as CVE-2022-0540, which has a CVSS score of 9.9
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Atlassian has released updates for Jira and Jira Service Management that addresses a critical authentication bypass vulnerability in its web authentication framework, Jira Seraph. An unauthenticated, remote attacker could exploit this vulnerability by sending a specially crafted HTTP request to bypass authentication and authorisation requirements in WebWork actions using an affected configuration and take control of the system.
Remediation advice
Affected organisations are encouraged to review the Atlassian Jira Security Advisory 2022-04-20 and FAQ for CVE-2022-0540 and apply the necessary updates or workarounds.
Definitive source of threat updates
Last edited: 22 April 2022 8:59 am