CVE-2023-22501
published 2023-02-01CVE-2023-22501: An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain…
PriorityP269critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
15.98%
96.5th percentile
An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and outgoing email enabled on a Jira Service Management instance, an attacker could gain access to signup tokens sent to users with accounts that have never been logged into. Access to these tokens can be obtained in two cases:
* If the attacker is included on Jira issues or requests with these users, or
* If the attacker is forwarded or otherwise gains access to emails containing a “View Request” link from these users.
Bot accounts are particularly susceptible to this scenario. On instances with single sign-on, external customer accounts can be affected in projects where anyone can create their own account.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | jira_service_management | — | — |
| atlassian | jira_service_management | >= 5.3.0 < 5.3.3 | 5.3.3 |
| atlassian | jira_service_management | >= 5.4.0 < 5.4.2 | 5.4.2 |
| atlassian | jira_service_management_data_center | — | — |
| atlassian | jira_service_management_data_center | — | — |
| atlassian | jira_service_management_data_center | — | — |
| atlassian | jira_service_management_data_center | — | — |
| atlassian | jira_service_management_server | — | — |
| atlassian | jira_service_management_server | — | — |
| atlassian | jira_service_management_server | — | — |
| atlassian | jira_service_management_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Bot accounts are a high-value target for this attack vector; prioritize monitoring/auditing bot account activity on Jira Service Management instances ↗
- →On SSO-enabled instances, monitor for unexpected external customer account access in projects where self-registration is permitted ↗
- →Vulnerable versions are Jira Service Management 5.3.0, 5.3.1, 5.3.2, 5.4.0, 5.4.1, and 5.5.0; flag any instances running these versions ↗
- →Exploitation requires write access to the User Directory and outgoing email enabled; audit these configuration states as risk indicators ↗
- →Affected versions span 5.3.0 through 5.5.0; use this range for asset inventory and patch-gap detection ↗
- ·Exploitation requires write access to the User Directory AND outgoing email enabled on the instance; both conditions must be present for the attack to succeed ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv3.09.4CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Sentinelone
CVE-2023-22501: Atlassian Jira Service Management Vulnerability
blogs_sentinelone·2023-02-07·CVSS 9.1
CVE-2023-22501 [CRITICAL] CVE-2023-22501: Atlassian Jira Service Management Vulnerability
The CVE-2023-22501 (CVSS score of 9.4) was caused by an error in the authentication validation process. An attacker could perform a specially crafted request to access a user’s account and gain access to a Jira service management instance. The vulnerability has been rated as critical by Atlassian.
In response to a critical security issue in Jira’s Data Center and Service Management Server, Atlassian has released fixes . The vulnerability could allow an attacker to access sensitive instances without being detected.
## About CVE-2023-22501
The vulnerability was found in Jira’s Data Center, and the Service Management Server allows an attacker to access a Jira service management instance by impersonating a user under certain circumstances.
With write access to the user directory and an out
Sentinelone
CVE-2023-22501: Atlassian Jira Service Management Vulnerability
blogs_sentinelone·2023-02-07·CVSS 9.1
CVE-2023-22501 [CRITICAL] CVE-2023-22501: Atlassian Jira Service Management Vulnerability
The CVE-2023-22501 (CVSS score of 9.4) was caused by an error in the authentication validation process. An attacker could perform a specially crafted request to access a user’s account and gain access to a Jira service management instance. The vulnerability has been rated as critical by Atlassian.
In response to a critical security issue in Jira’s Data Center and Service Management Server, Atlassian has released fixes. The vulnerability could allow an attacker to access sensitive instances without being detected.
## About CVE-2023-22501
The vulnerability was found in Jira’s Data Center, and the Service Management Server allows an attacker to access a Jira service management instance by impersonating a user under certain circumstances.
With write access to the user directory and an outg
Checkpoint
6th February – Threat Intelligence Report
blogs_checkpoint·2023-02-06
CVE-2022-31711 6th February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 6th February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 6th February, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHE
Check Point Research has flagged the Dingo crypto Token, with a market cap of $10,941,525 as a scam. The threat actors behind the token added a backdoor function in its smart contract, to manipulate the fee. Specifically, they used the “setTaxFeePercent” function within the token’s smart contract code to manipulate the buyin
Sentinelone
CVE-2022-23529: Revocation of JsonWebToken Vulnerability
blogs_sentinelone·2023-01-19
CVE-2022-23529 CVE-2022-23529: Revocation of JsonWebToken Vulnerability
## Update: As of January 12, 2023
The vulnerability in JsonWebToken, CVE-2022-23529, discovered by Unit 42 researchers on January 9, 2023, has been revoked. It says that if specific conditions meet, an attacker could potentially execute code on a server verifying a malicious JSON web token request.
However, the likelihood of this happening in real-world situations is considered low due to the specific requirements needed for exploitation.
After careful consideration, it has been decided that the vulnerability is invalid, and CVE-2022-23529 is being revoked. However, the revocation may take some time to propagate throughout the entire system.
The maintainers and researchers are also updating their respective advisories to include more context around the issue and potential exploitation.
2023-02-01
Published