CVE-2023-22501
Jira Service Management vulnerability analysis and mitigation

Overview

An authentication vulnerability (CVE-2023-22501) was discovered in Jira Service Management Server and Data Center, disclosed on February 1, 2023. The vulnerability allows an attacker to impersonate another user and gain unauthorized access to a Jira Service Management instance under specific conditions. The affected versions include 5.3.0, 5.3.1, 5.3.2, 5.4.0, 5.4.1, and 5.5.0. Notably, Atlassian Cloud instances are not affected by this vulnerability (Rapid7 Blog, Atlassian FAQ).

Technical details

The vulnerability is rated as Critical with a CVSS v3.1 base score of 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). The flaw requires write access to a User Directory and outgoing email enabled on the Jira Service Management instance. An attacker can gain access to signup tokens sent to users with accounts that have never been logged into through two methods: either by being included on Jira issues/requests with these users, or by gaining access to emails containing a 'View Request' link from these users. Bot accounts are particularly vulnerable to this scenario (NVD, Atlassian Advisory).

Impact

The vulnerability can lead to unauthorized access and user impersonation in affected Jira Service Management instances. On instances with single sign-on, external customer accounts can be affected in projects where anyone can create their own account. When exploited, the attacker can gain unauthorized access to the system with the privileges of the impersonated user, and no notification is sent when the password is changed (Atlassian FAQ).

Exploitability

As of February 6, 2023, the vulnerability was not known to be exploited in the wild. However, given Atlassian products' popularity among attackers in the past two years, the risk is considered significant. The vulnerability is particularly concerning for bot accounts and systems with enabled public signup features (Rapid7 Blog).

Mitigation and workarounds

Organizations should update to the fixed versions (5.3.3, 5.4.2, 5.5.1, or 5.6.0) as soon as possible. For those unable to immediately upgrade, Atlassian provides a temporary workaround through manually upgrading the version-specific servicedesk-variable-substitution-plugin JAR file. After upgrading, organizations can identify potentially compromised accounts by checking for accounts that had password changes and have been logged into since the vulnerable version was installed (Atlassian FAQ).

Additional resources


SourceThis report was generated using AI

Related Jira Service Management vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-1471CRITICAL9.8
  • IBM Db2 logoIBM Db2
  • stargate
NoYesDec 01, 2022
CVE-2023-22501CRITICAL9.1
  • Jira Service Management logoJira Service Management
  • cpe:2.3:a:atlassian:jira_service_desk
NoYesFeb 01, 2023
CVE-2024-21683HIGH8.8
  • Atlassian Fisheye & Crucible logoAtlassian Fisheye & Crucible
  • crucible
NoYesMay 21, 2024
CVE-2025-22157HIGH7.2
  • JIRA logoJIRA
  • cpe:2.3:a:atlassian:jira_service_management
NoYesMay 20, 2025
CVE-2022-36800MEDIUM4.3
  • Jira Service Management logoJira Service Management
  • cpe:2.3:a:atlassian:jira_service_management
NoYesAug 03, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management