CVE-2022-0540
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.8epss 88%
from disclosure to weapon35 days
Published on NVDApr 20
1st PoC+35d
VulnCheck+710d
exploitation probability
88%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Management Server and Data Center versions before 4.13.18, versions 4.14.0 and later before 4.20.6, and versions 4.21.0 and later before 4.22.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Atlassian · Jira Core ServerAtlassian · Jira Service Management Data CenterAtlassian · Jira Service Management ServerAtlassian · Jira Software Data CenterAtlassian · Jira Software Serverpublic PoCs found — 2
githubgithub.com/Pear1y/CVE-2022-0540-RCE★ 71vulncheckvulncheck.com/xdb/d7c7241b0ca7unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.