CVE-2022-0540

Description

A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Management Server and Data Center versions before 4.13.18, versions 4.14.0 and later before 4.20.6, and versions 4.21.0 and later before 4.22.0.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
92.485

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2015-8481,CVE-2022-0540 are affected in Atlassian Jira Core Server 7.0.3Windows
Multiple Vulnerabilities are affected in Atlassian Jira Core Data Center 8.5.9Windows
Multiple Vulnerabilities are affected in Atlassian Jira Core Data Center 8.20.3Windows
Multiple Vulnerabilities are affected in Atlassian Jira Core Data Center 8.21.0Windows
Vulnerabilities CVE-2022-0540 are affected in Atlassian Jira Core Server *Windows
Vulnerabilities CVE-2019-13990,CVE-2022-0540 are affected in Atlassian Jira Service Management Data Center 4.20.5Windows
Vulnerabilities CVE-2019-13990,CVE-2022-0540 are affected in Atlassian Jira Service Management Server 4.20.5Windows
Vulnerabilities CVE-2022-0540 are affected in Atlassian Jira Service Management Data Center 4.13.17Windows
Vulnerabilities CVE-2022-0540 are affected in Atlassian Jira Service Management Data Center 4.13.7Windows
Vulnerabilities CVE-2022-0540 are affected in Atlassian Jira Service Management Data Center 4.21.99Windows
Vulnerabilities CVE-2022-0540 are affected in Atlassian Jira Service Management Server 4.13.17Windows
Vulnerabilities CVE-2022-0540 are affected in Atlassian Jira Service Management Server 4.13.7Windows
Vulnerabilities CVE-2022-0540 are affected in Atlassian Jira Service Management Server 4.21.99Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234