CVE-2022-0540
9.8
CRITICAL · CVSS 3.1 · EPSS 88.1% (pctl 100)
Patch early
EPSS 88.1% — above the 10% action threshold.
Description
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Management Server and Data Center versions before 4.13.18, versions 4.14.0 and later before 4.20.6, and versions 4.21.0 and later before 4.22.0.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 88.06% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-04-20 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| atlassian | jira data center |
| atlassian | jira server |
| atlassian | jira service management |
References
- https://confluence.atlassian.com/display/JIRA/Jira+Security+Advisory+2022-04-20
- https://jira.atlassian.com/browse/JRASERVER-73650
- https://jira.atlassian.com/browse/JSDSERVER-11224
- https://confluence.atlassian.com/display/JIRA/Jira+Security+Advisory+2022-04-20
- https://jira.atlassian.com/browse/JRASERVER-73650
- https://jira.atlassian.com/browse/JSDSERVER-11224
→ the Explorer · watch your stack · NVD