CVE-2025-22157Improper Access Control in Atlassian Jira Data Center

Severity
7.2HIGHNVD
EPSS
0.3%
top 47.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 20

Description

This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center and Server This PrivEsc (Privilege Escalation) vulnerability, with a CVSS Score of 7.2, allows an attacker to perform actions as a higher-privileged user. Atlassian recommends that Jira Core Data Center and Server and Jira Service Management Data Center and S

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages6 packages

CVEListV5atlassian/jira_core_data_center4 versions+3
NVDatlassian/jira_data_center5.12.05.12.20+3
CVEListV5atlassian/jira_service_management_server5.12.0 to 5.12.19
CVEListV5atlassian/jira_core_server9.12.0 to 9.12.19

Patches

🔴Vulnerability Details

2
CVEList
CVE-2025-22157: This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 92025-05-20
GHSA
GHSA-352j-376q-2pmc: This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 92025-05-20
CVE-2025-22157 — Improper Access Control in Atlassian | cvebase