[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250039

 
 

909

 
 

195882

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Server-side request forgery vulnerability in Atlassian Jira Server - CVE-2022-26135 (linux)

ID: oval:org.secpod.oval:def:91101Date: (C)2023-07-19   (M)2023-07-19
Class: VULNERABILITYFamily: unix




The host is installed with Atlassian Jira Server 8.0.0 before 8.13.22, 8.14.0 before 8.20.10, or 8.21.0 before 8.22.4 and is prone to a server-side request forgery vulnerability. A flaw is present in the application which fails to properly handle the Mobile Plugin for Jira Data Center and Server. Successful exploitation could allows a remote, authenticated attacker to perform a full read server-side request forgery via a batch endpoint.

Platform:
Linux
Product:
Atlassian Jira Server
Reference:
CVE-2022-26135
CVE    1
CVE-2022-26135

© SecPod Technologies