A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Management Server and Data Center versions before 4.13.18, versions 4.14.0 and later before 4.20.6, and versions 4.21.0 and later before 4.22.0.
References
Link Resource
https://confluence.atlassian.com/display/JIRA/Jira+Security+Advisory+2022-04-20 Issue Tracking Patch Vendor Advisory
https://jira.atlassian.com/browse/JRASERVER-73650 Issue Tracking Patch Vendor Advisory
https://jira.atlassian.com/browse/JSDSERVER-11224 Issue Tracking Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: atlassian

Published: 2022-04-20T00:00:00

Updated: 2022-04-20T18:30:17

Reserved: 2022-02-08T00:00:00


Link: CVE-2022-0540

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-04-20T19:15:07.680

Modified: 2023-08-08T14:22:24.967


Link: CVE-2022-0540

JSON object: View

cve-icon Redhat Information

No data.