Record summary

CVE-2022-39960 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all groups from the Jira instance by making a groupexport_download=true request to a plugins/servlet/groupexportforjira/admin/ URI.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 13, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMJira Netic Group Export <1.0.3 - Missing AuthorizationCVSS 5.3

Jira Netic Group Export add-on before 1.0.3 contains a missing authorization vulnerability. The add-on does not perform authorization checks, which can allow an unauthenticated user to export all groups from the Jira instance by making a groupexport_download=true request to a plugins/servlet/groupexportforjira/admin/ URI and thereby potentially obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to gain unauthorized access to sensitive data.

Remediation

Upgrade to Jira Netic Group Export version 1.0.3 or later to fix the missing authorization issue.

WeaknessesCWE-862
AuthorsFor3stCo1d
Template tagscvecve2022atlassianjiraneticunauthvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:netic:group_export:*:*:*:*:*:jira:*:*
Shodan: http.component:"Atlassian Jira"
Shodan: http.component:"atlassian jira"

Source: ProjectDiscovery

References

3