CVE-2023-22501
https://notcve.org/view.php?id=CVE-2023-22501
An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and outgoing email enabled on a Jira Service Management instance, an attacker could gain access to signup tokens sent to users with accounts that have never been logged into. Access to these tokens can be obtained in two cases: * If the attacker is included on Jira issues or requests with these users, or * If the attacker is forwarded or otherwise gains access to emails containing a “View Request” link from these users. Bot accounts are particularly susceptible to this scenario. On instances with single sign-on, external customer accounts can be affected in projects where anyone can create their own account. • https://jira.atlassian.com/browse/JSDSERVER-12312 • CWE-287: Improper Authentication •
CVE-2022-36803
https://notcve.org/view.php?id=CVE-2022-36803
The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox. La API MasterUserEdit en Atlassian Jira Align Server versiones anteriores a 10.109.2, permite a un atacante autenticado con el permiso de rol People usar la API MasterUserEdit para modificar el rol de cualquier usuario a Super Admin. Esta vulnerabilidad fue reportada por Jacob Shafer de Bishop Fox • https://jira.atlassian.com/browse/JIRAALIGN-4281 • CWE-276: Incorrect Default Permissions •
CVE-2022-36802
https://notcve.org/view.php?id=CVE-2022-36802
The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery. This can be exploited by a remote, unauthenticated attacker with Super Admin privileges by sending a specially crafted HTTP request. La API ManageJiraConnectors en Atlassian Jira Align versiones anteriores a 10.109.2, permite a atacantes remotos explotar este problema para acceder a recursos de red internos por medio de un ataque de tipo Server-Side Request Forgery. Esto puede ser explotado por un atacante remoto, no autenticado, con privilegios de Super Admin, mediante el envío de una petición HTTP especialmente diseñada • https://jira.atlassian.com/browse/JIRAALIGN-4326 • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2022-36801
https://notcve.org/view.php?id=CVE-2022-36801
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint. The affected versions are before version 8.20.8. Las versiones afectadas de Atlassian Jira Server y Data Center permiten a atacantes remotos anónimos inyectar HTML o JavaScript arbitrario por medio de una vulnerabilidad de tipo Cross-Site Scripting (RXSS) Reflejado en el endpoint TeamManagement.jspa. Las versiones afectadas son anteriores a versión 8.20.8 • https://jira.atlassian.com/browse/JRASERVER-73740 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-36800
https://notcve.org/view.php?id=CVE-2022-36800
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version 4.22.2. Las versiones afectadas de Atlassian Jira Service Management Server y Data Center permiten a atacantes remotos sin el permiso "Browse Users" visualizar los grupos por medio de una vulnerabilidad de divulgación de información en el endpoint browsegroups.action. Las versiones afectadas son anteriores a 4.22.2 • https://jira.atlassian.com/browse/JSDSERVER-11900 • CWE-732: Incorrect Permission Assignment for Critical Resource •