Atlassian Releases Security Updates for Jira Service Management Server and Data Center
Atlassian security updates address critical vulnerability known as CVE-2023-22501
Summary
Atlassian security updates address critical vulnerability known as CVE-2023-22501
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Atlassian has released an update for an authentication vulnerability, which has a CVSS score of 9.4. This vulnerability could enable an attacker to impersonate another user in order to access a Jira Service Management instance. Under the right conditions, a remote attacker could intercept sign-up tokens to gain access to the affected system.
Remediation advice
Affected organisations are encouraged to review the Atlassian Security Advisory and apply any relevant updates or mitigations.
Definitive source of threat updates
Last edited: 3 February 2023 2:53 pm