cbcvebase.
CVE-2023-22501
published 2023-02-01

CVE-2023-22501: An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain…

PriorityP269critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
15.98%
96.6th percentile
An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and outgoing email enabled on a Jira Service Management instance, an attacker could gain access to signup tokens sent to users with accounts that have never been logged into. Access to these tokens can be obtained in two cases: * If the attacker is included on Jira issues or requests with these users, or * If the attacker is forwarded or otherwise gains access to emails containing a “View Request” link from these users. Bot accounts are particularly susceptible to this scenario. On instances with single sign-on, external customer accounts can be affected in projects where anyone can create their own account.

Affected

11 ranges
VendorProductVersion rangeFixed in
atlassianjira_service_management
atlassianjira_service_management>= 5.3.0 < 5.3.35.3.3
atlassianjira_service_management>= 5.4.0 < 5.4.25.4.2
atlassianjira_service_management_data_center
atlassianjira_service_management_data_center
atlassianjira_service_management_data_center
atlassianjira_service_management_data_center
atlassianjira_service_management_server
atlassianjira_service_management_server
atlassianjira_service_management_server
atlassianjira_service_management_server

Detection & IOCsextracted from sources · hover to see the quote

  • Bot accounts are a high-value target for this attack vector; prioritize monitoring/auditing bot account activity on Jira Service Management instances
  • On SSO-enabled instances, monitor for unexpected external customer account access in projects where self-registration is permitted
  • Vulnerable versions are Jira Service Management 5.3.0, 5.3.1, 5.3.2, 5.4.0, 5.4.1, and 5.5.0; flag any instances running these versions
  • Exploitation requires write access to the User Directory and outgoing email enabled; audit these configuration states as risk indicators
  • Affected versions span 5.3.0 through 5.5.0; use this range for asset inventory and patch-gap detection
  • ·Exploitation requires write access to the User Directory AND outgoing email enabled on the instance; both conditions must be present for the attack to succeed

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv3.09.4CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.