CVE Vulnerabilities

CVE-2025-22175

Published: Oct 22, 2025 | Modified: Oct 24, 2025
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another users private checklist.

Affected Software

Name Vendor Start Version End Version
Jira_align Atlassian 11.14.0 (including) 11.16.1 (excluding)

References