Atlassian has identified and released fixes for a critical security vulnerability in Jira Service Management Server and Data Center. This vulnerability, tracked as CVE-2023-22501, is a case of broken authentication with low attack complexity. It allows an attacker to impersonate another user and gain unauthorized access to a Jira Service Management instance. This vulnerability was introduced in version 5.3.0 and affects all subsequent versions. Fixes have been made available in versions 5.3.3, 5.3.3, 5.5.1, and 5.6.0 or later. The vulnerability can be exploited if write access to a User Directory and outgoing email are enabled on a Jira Service Management instance. The attacker can gain access to signup tokens sent to users with accounts that have never been logged into. Jira sites hosted on the cloud via an atlassian[. Net domain are not affected by the flaw and no action is required in this case. It is important for users to upgrade their installations to the latest versions to protect against potential threats.
This Cyber News was published on thehackernews.com. Publication date: Fri, 03 Feb 2023 12:47:02 +0000