Atlassian patched CVE-2022-26135, an authenticated server-side request forgery (SSRF) flaw in Jira Core and Jira Service Desk. The issue allowed an attacker to cause a vulnerable Jira instance to send requests to arbitrary URLs with attacker-controlled HTTP methods, headers, and request bodies; deployments with open user registration could be exposed without an attacker first obtaining an account.
An attacker could use the flaw to reach internal-only services and, in cloud-hosted environments, query cloud metadata endpoints to obtain sensitive information or potentially cloud credentials. Organizations running affected Jira Server or Data Center deployments should apply Atlassian’s June 2022 security updates and restrict unauthenticated sign-up, while reviewing access to metadata services and internal endpoints from Jira hosts.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Atlassian published a security advisory and patches for CVE-2022-26135, an authenticated Jira SSRF issue allowing attacker-controlled requests to arbitrary URLs. Assetnote Security Research Team received discovery credit.
Atlassian confirmed the planned publication date for its security advisory and requested credit information from the Assetnote researchers.
The Assetnote Security Research Team disclosed an authenticated SSRF vulnerability affecting Jira Core and Jira Service Desk to Atlassian. Atlassian confirmed and triaged the report the same day.
Researchers documented that the Jira Mobile Plugin batch API at /rest/nativemobile/1.0/batch could be abused through attacker-controlled URL construction to send up to five server-side requests with selected methods, headers, and bodies. They also described how enabled Jira Service Desk customer self-registration could supply an account for exploiting the otherwise authenticated SSRF.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
slcyber.io
Open sourceslcyber.io
Open sourceconfluence.atlassian.com
Open sourceblog.assetnote.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.