
Cloud Vulnerability DB
A community-led vulnerabilities database
An authentication vulnerability (CVE-2023-22501) was discovered in Jira Service Management Server and Data Center, disclosed on February 1, 2023. The vulnerability allows an attacker to impersonate another user and gain unauthorized access to a Jira Service Management instance under specific conditions. The affected versions include 5.3.0, 5.3.1, 5.3.2, 5.4.0, 5.4.1, and 5.5.0. Notably, Atlassian Cloud instances are not affected by this vulnerability (Rapid7 Blog, Atlassian FAQ).
The vulnerability is rated as Critical with a CVSS v3.1 base score of 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). The flaw requires write access to a User Directory and outgoing email enabled on the Jira Service Management instance. An attacker can gain access to signup tokens sent to users with accounts that have never been logged into through two methods: either by being included on Jira issues/requests with these users, or by gaining access to emails containing a 'View Request' link from these users. Bot accounts are particularly vulnerable to this scenario (NVD, Atlassian Advisory).
The vulnerability can lead to unauthorized access and user impersonation in affected Jira Service Management instances. On instances with single sign-on, external customer accounts can be affected in projects where anyone can create their own account. When exploited, the attacker can gain unauthorized access to the system with the privileges of the impersonated user, and no notification is sent when the password is changed (Atlassian FAQ).
As of February 6, 2023, the vulnerability was not known to be exploited in the wild. However, given Atlassian products' popularity among attackers in the past two years, the risk is considered significant. The vulnerability is particularly concerning for bot accounts and systems with enabled public signup features (Rapid7 Blog).
Organizations should update to the fixed versions (5.3.3, 5.4.2, 5.5.1, or 5.6.0) as soon as possible. For those unable to immediately upgrade, Atlassian provides a temporary workaround through manually upgrading the version-specific servicedesk-variable-substitution-plugin JAR file. After upgrading, organizations can identify potentially compromised accounts by checking for accounts that had password changes and have been logged into since the vulnerable version was installed (Atlassian FAQ).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."