atlassian jira_align CVE Vulnerabilities (13)

CVEs: 13 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting atlassian jira_align (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 113 of 13 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-22178 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page. [email protected] 5.3 0.17% 2025-10-22 2026-06-17
CVE-2025-22177 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews. [email protected] 5.3 0.17% 2025-10-22 2026-06-17
CVE-2025-22176 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items. [email protected] 5.3 0.17% 2025-10-22 2026-06-17
CVE-2025-22175 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist. [email protected] 5.3 0.16% 2025-10-22 2026-06-17
CVE-2025-22174 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission. [email protected] 5.3 0.17% 2025-10-22 2026-06-17
CVE-2025-22173 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission. [email protected] 5.3 0.17% 2025-10-22 2026-06-17
CVE-2025-22172 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission. [email protected] 5.3 0.17% 2025-10-22 2026-06-17
CVE-2025-22171 Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users. [email protected] 5.3 0.16% 2025-10-22 2026-06-17
CVE-2025-22170 Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action. [email protected] 5.3 0.17% 2025-10-22 2026-06-17
CVE-2025-22169 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level. [email protected] 5.3 0.16% 2025-10-22 2026-06-17
CVE-2025-22168 Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist. [email protected] 5.3 0.17% 2025-10-22 2026-06-17
CVE-2022-36803 The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox. [email protected] 8.8 0.56% 2022-10-14 2026-06-17
CVE-2022-36802 The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery. This can be exploited by a remote, unauthenticated attacker with Super Admin privileges by sending a specially crafted HTTP request. [email protected] 4.9 0.83% 2022-10-14 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence