Vulnerabilities > Atlassian > Jira Align

DATE CVE VULNERABILITY TITLE RISK
2022-10-14 CVE-2022-36802 Server-Side Request Forgery (SSRF) vulnerability in Atlassian Jira Align
The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery.
network
low complexity
atlassian CWE-918
4.9
2022-10-14 CVE-2022-36803 Incorrect Default Permissions vulnerability in Atlassian Jira Align
The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin.
network
low complexity
atlassian CWE-276
8.8