CVE-2022-0540criticalobserved exploitationCWE-287

CVE-2022-0540: critical vulnerability in Atlassian Jira Service Management Server

Published · Updated

100Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.8epss 88%
from disclosure to weapon35 days
Published on NVDApr 20
1st PoC+35d
VulnCheck+710d
exploitation probability
88%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Management Server and Data Center versions before 4.13.18, versions 4.14.0 and later before 4.20.6, and versions 4.21.0 and later before 4.22.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.