Rewterz
Rewterz Threat Alert – DJVU Ransomware – Active IOCs
July 1, 2022
Rewterz
Rewterz Threat Alert – Qakbot (Qbot) Malware – Active IOCs
July 1, 2022

Rewterz Threat Advisory –CVE-2022-26135 – Atlassian Jira Data Center and Server server-side Vulnerability

Severity

High

Analysis Summary

CVE-2022-26135

Atlassian is vulnerable to server-side request forgery, caused by a flaw in the Mobile Plugin. By using a specially-crafted argument, an attacker could exploit this vulnerability to conduct a full-read SSRF attack.

Impact

  • Unauthorized Access

Indicators Of Compromise

CVE

  • CVE-2022-26135

Affected Vendors

Atlassian

Affected Products

  • Atlassian Jira Software Data Center 8.14.0
  • Atlassian Jira Software Data Center 8.15.0
  • Atlassian Jira Server 8.20.0
  • Atlassian jira Software Data Center 8.13.0

Remediation

Refer to Jira Server Security Advisory for patch, upgrade or suggested workaround information.

Jira Server Security Advisory