Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-36802


The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery. This can be exploited by a remote, unauthenticated attacker with Super Admin privileges by sending a specially crafted HTTP request.


Published

2022-10-14T04:15:13.703

Last Modified

2024-11-21T07:13:48.147

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.9 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-918
  • Type: Secondary
    CWE-918

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application atlassian jira_align < 10.109.2 Yes

References