Atlassian has published security advisory CVE-2022-0540 today, 29 June 2022. This advisory is in regards to and affects the Jira Server Mobile Plugin which is bundled with Jira and Jira Service Management. Jira Cloud is not affected. The goal of this article is to help raise awareness for this critical vulnerability and to provide you a means to ask further questions about this in Community if needed.
Please review the complete advisory in CVE-2022-26135 - Full-Read Server Side Request Forgery in Mobile Plugin for Jira Data Center and Server and the FAQ page FAQ for CVE-202226135
Earl McCutcheon
Atlassian Community Support
Atlassian
498 accepted answers
Did you catch the news at Team ‘25? With Loom, Confluence, Atlassian Intelligence, & even Jira 👀, you won’t have to worry about taking meeting notes again… unless you want to. Join us to explore the beta & discover a new way to boost meeting productivity.
Register today!Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
1 comment