CVE-2022-39960
netic group_export Missing Authorization
Record summary
CVE-2022-39960 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all groups from the Jira instance by making a groupexport_download=true request to a plugins/servlet/groupexportforjira/admin/ URI.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 13, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
group_exportBrowse netic / group_export | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMJira Netic Group Export <1.0.3 - Missing AuthorizationCVSS 5.3
Jira Netic Group Export add-on before 1.0.3 contains a missing authorization vulnerability. The add-on does not perform authorization checks, which can allow an unauthenticated user to export all groups from the Jira instance by making a groupexport_download=true request to a plugins/servlet/groupexportforjira/admin/ URI and thereby potentially obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to gain unauthorized access to sensitive data.
Remediation
Upgrade to Jira Netic Group Export version 1.0.3 or later to fix the missing authorization issue.
Source: ProjectDiscovery