Atlassian has published security advisory CVE-2022-0540 today, 29 June 2022. This advisory is in regards to and affects the Jira Server Mobile Plugin which is bundled with Jira and Jira Service Management. Jira Cloud is not affected. The goal of this article is to help raise awareness for this critical vulnerability and to provide you a means to ask further questions about this in Community if needed.
Please review the complete advisory in CVE-2022-26135 - Full-Read Server Side Request Forgery in Mobile Plugin for Jira Data Center and Server and the FAQ page FAQ for CVE-202226135
Earl McCutcheon
Atlassian Community Support
Atlassian
499 accepted answers
Join the largest European gathering of the Atlassian Community and reimagine what’s possible when great teams and transformative technology come together. Plus, grab your Super Fan ticket now and save over €1,000 on your pass before prices rise on 3 June.
Register nowOnline forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
1 comment