CVE-2022-38367

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/09/2022
Last modified:
08/09/2022

Description

The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netic:user_export_for_jira:*:*:*:*:*:*:*:* 2.0.6 (excluding)