CVE-2025-22167
JIRA vulnerability analysis and mitigation

Overview

CVE-2025-22167 is a Path Traversal (Arbitrary Write) vulnerability in Atlassian Jira Software Data Center and Server that allows an authenticated attacker to modify any filesystem path writable by the Jira JVM process. The vulnerability was introduced in versions 9.12.0, 10.3.0, and 11.0.0, and was publicly disclosed on October 21, 2025, via Atlassian's monthly security bulletin. It carries a CVSS v4.0 score of 8.7 (High) as assigned by Atlassian, and a CVSS v3.1 score of 6.5 (Medium) as assessed by NVD (Atlassian Advisory, Atlassian Bulletin). The vulnerability was reported through Atlassian's internal bug bounty program and also affects Jira Service Management Data Center and Server under the same CVE identifier (Atlassian Bulletin).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'), where insufficient validation of user-supplied file path inputs allows an attacker to traverse outside the intended directory (Atlassian Advisory). The attack vector is network-based, requires low privileges (an authenticated user account), no user interaction, and low attack complexity, making it accessible to any authenticated Jira user. Exploitation allows the attacker to write arbitrary content to any filesystem path accessible to the Jira JVM process, which could include configuration files, application binaries, or other sensitive system paths. A proof-of-concept repository has appeared on GitHub (GitHub PoC), though detailed technical write-ups on the specific vulnerable endpoint or payload structure have not been widely published.

Impact

Successful exploitation enables an authenticated attacker with low-level privileges to overwrite or create arbitrary files on the server filesystem, limited to paths writable by the Jira JVM process. This could lead to remote code execution by overwriting application scripts, configuration files, or deploying malicious artifacts, resulting in full system compromise (Atlassian Advisory). The vulnerability also affects Jira Service Management Data Center and Server, broadening the scope of potentially impacted enterprise environments. Lateral movement is possible if the compromised Jira server has access to shared network resources or if the JVM process runs with elevated OS-level privileges.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible Jira Software Data Center or Server instances running versions 9.12.0–9.12.27, 10.3.0–10.3.11, or 11.0.0–11.0.x using tools like Shodan, Censys, or internal network scanning.
  2. Authentication: Obtain valid low-privilege Jira user credentials (e.g., through phishing, credential stuffing, or use of a legitimate account).
  3. Identify vulnerable endpoint: Locate the application functionality that processes file path inputs without adequate sanitization — likely a file upload, attachment, or export feature within Jira.
  4. Craft path traversal payload: Construct a request containing a path traversal sequence (e.g., ../../) in the filename or path parameter to target a writable filesystem location outside the intended directory, such as a Jira configuration file or a web-accessible directory.
  5. Write malicious content: Submit the crafted request to write a malicious file (e.g., a JSP web shell or modified configuration) to the targeted path accessible by the Jira JVM process.
  6. Achieve code execution or persistence: If a web shell is successfully written to a web-accessible directory, access it via HTTP to execute arbitrary OS commands, establish persistence, or pivot to other systems (Atlassian Advisory, GitHub PoC).

Indicators of compromise

  • Network: Unusual HTTP requests containing path traversal sequences (../, ..%2F, ..%5C) in file path or filename parameters sent to Jira endpoints; unexpected outbound connections from the Jira server to external IPs.
  • File System: Unexpected files (e.g., JSP web shells, modified .properties or .xml config files) appearing in Jira installation directories or web-accessible paths; modification timestamps on critical configuration files inconsistent with normal operations.
  • Logs: Jira access logs showing requests with encoded path traversal patterns in parameters; Java exceptions or errors related to file write operations in atlassian-jira.log.
  • Process: Unusual child processes spawned by the Jira JVM (e.g., cmd.exe, /bin/bash, curl, wget) indicating potential post-exploitation activity.

Mitigation and workarounds

Atlassian recommends upgrading to the following fixed versions: Jira Software Data Center and Server 9.12.28 or later, 10.3.12 or later, or 11.1.0 or later (Atlassian Advisory). The same fixed versions apply to Jira Service Management Data Center and Server. No official configuration-based workaround has been provided; upgrading is the primary remediation. As interim measures, organizations should limit network access to Jira instances, enforce the principle of least privilege for the Jira service account, and monitor for unauthorized file modifications on the server filesystem.

Community reactions

The vulnerability received coverage from multiple security news outlets including SecurityOnline, GBHackers, CyberSecurityNews, and CyberPress, highlighting the risk of arbitrary file modification via JVM access (SecurityOnline, GBHackers). The Hacker News included it in their weekly security recap (The Hacker News). Black Kite flagged it as a notable third-party risk in their Focus Friday analysis (Black Kite). Community discussion on Reddit's r/pwnhub and r/CVEWatch noted it as a trending CVE in the days following disclosure.

Additional resources


SourceThis report was generated using AI

Related JIRA vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-1471CRITICAL9.8
  • IBM Db2 logoIBM Db2
  • prometheus-jmx-exporter-openjdk8
NoYesDec 01, 2022
CVE-2025-22167HIGH8.7
  • JIRA logoJIRA
  • cpe:2.3:a:atlassian:jira
NoYesOct 22, 2025
CVE-2025-22157HIGH7.2
  • JIRA logoJIRA
  • cpe:2.3:a:atlassian:jira_service_management
NoYesMay 20, 2025
CVE-2022-36799HIGH7.2
  • JIRA logoJIRA
  • cpe:2.3:a:atlassian:jira
NoYesAug 01, 2022
CVE-2024-21685MEDIUM6.5
  • JIRA logoJIRA
  • cpe:2.3:a:atlassian:jira
NoYesJun 18, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management