Atlassian Jira Align vulnerabilities

13 known vulnerabilities affecting atlassian/jira_align.

Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM12

Vulnerabilities

Page 1 of 1
CVE-2025-22169MEDIUMCVSS 5.3≥ 11.14.0, < 11.16.1v>= 11.14.0+4 more2025-10-22
CVE-2025-22169 [MEDIUM] CWE-285 CVE-2025-22169: Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpo Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level.
cvelistv5nvd
CVE-2025-22173MEDIUMCVSS 5.3≥ 11.14.0, < 11.16.1v>= 11.14.0+4 more2025-10-22
CVE-2025-22173 [MEDIUM] CWE-285 CVE-2025-22173: Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpo Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission.
cvelistv5nvd
CVE-2025-22172MEDIUMCVSS 5.3≥ 11.14.0, < 11.16.1v>= 11.14.0+4 more2025-10-22
CVE-2025-22172 [MEDIUM] CWE-285 CVE-2025-22172: Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpo Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission.
cvelistv5nvd
CVE-2025-22170MEDIUMCVSS 5.3≥ 11.14.0, < 11.16.1v>= 11.14.0+4 more2025-10-22
CVE-2025-22170 [MEDIUM] CWE-285 CVE-2025-22170: Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileg Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action.
cvelistv5nvd
CVE-2025-22177MEDIUMCVSS 5.3≥ 11.14.0, < 11.16.1v>= 11.14.0+4 more2025-10-22
CVE-2025-22177 [MEDIUM] CWE-285 CVE-2025-22177: Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpo Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.
cvelistv5nvd
CVE-2025-22175MEDIUMCVSS 5.3≥ 11.14.0, < 11.16.1v>= 11.14.0+4 more2025-10-22
CVE-2025-22175 [MEDIUM] CWE-285 CVE-2025-22175: Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpo Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.
cvelistv5nvd
CVE-2025-22178MEDIUMCVSS 5.3≥ 11.14.0, < 11.16.1v>= 11.14.0+4 more2025-10-22
CVE-2025-22178 [MEDIUM] CWE-862 CVE-2025-22178: Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpo Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.
cvelistv5nvd
CVE-2025-22174MEDIUMCVSS 5.3≥ 11.14.0, < 11.16.1v>= 11.14.0+4 more2025-10-22
CVE-2025-22174 [MEDIUM] CWE-285 CVE-2025-22174: Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpo Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.
cvelistv5nvd
CVE-2025-22168MEDIUMCVSS 5.3≥ 11.14.0, < 11.16.1v>= 11.14.0+4 more2025-10-22
CVE-2025-22168 [MEDIUM] CWE-285 CVE-2025-22168: Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpo Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist.
cvelistv5nvd
CVE-2025-22171MEDIUMCVSS 5.3≥ 11.14.0, < 11.16.1v>= 11.14.0+4 more2025-10-22
CVE-2025-22171 [MEDIUM] CWE-285 CVE-2025-22171: Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the privat Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.
cvelistv5nvd
CVE-2025-22176MEDIUMCVSS 5.3≥ 11.14.0, < 11.16.1v>= 11.14.0+4 more2025-10-22
CVE-2025-22176 [MEDIUM] CWE-285 CVE-2025-22176: Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpo Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.
cvelistv5nvd
CVE-2022-36803HIGHCVSS 8.8fixed in 10.109.2≥ unspecified, < 10.109.22022-10-14
CVE-2022-36803 [HIGH] CWE-276 CVE-2022-36803: The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticate The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox.
cvelistv5nvd
CVE-2022-36802MEDIUMCVSS 4.9fixed in 10.109.2≥ unspecified, < 10.109.22022-10-14
CVE-2022-36802 [MEDIUM] CWE-918 CVE-2022-36802: The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery. This can be exploited by a remote, unauthenticated attacker with Super Admin privileges by sending a specially crafted HTTP request.
cvelistv5nvd