HTTP: Jira Seraph Access Control Bypass

This signature detects attempts to exploit a known vulnerability against Atlassian Jira Seraph access control bypass . A successful attack can lead to security bypass.

Extended Description

A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Management Server and Data Center versions before 4.13.18, versions 4.14.0 and later before 4.20.6, and versions 4.21.0 and later before 4.22.0.

Affected Products

Atlassian jira_server

Short Name
HTTP:CTS:JIRA-SERAPH-AUTH
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Access Bypass CVE-2022-0540 Control Jira Seraph
Release Date
11/10/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Atlassian

Found a potential security threat?