CVE-2022-36800

MEDIUM

Atlassian Jira Service Management < 4.22.2 - Unauthenticated Information Disclosure via browsegroups.action Endpoint

Title source: llm
STIX 2.1

Description

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version 4.22.2.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JSDSERVER-11900

Scores

CVSS v3 4.3
EPSS 0.0053
EPSS Percentile 40.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (1)
atlassian/jira_service_management < 4.22.2 (2 CPE variants)
Published Aug 03, 2022
Tracked Since Feb 18, 2026