CVE-2022-36800

MEDIUM

Atlassian Jira Service Management - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version 4.22.2.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JSDSERVER-11900

Scores

CVSS v3 4.3
EPSS 0.0019
EPSS Percentile 41.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (1)
atlassian/jira_service_management < 4.22.2 (2 CPE variants)
Published Aug 03, 2022
Tracked Since Feb 18, 2026