CVE-2025-22175Medium· 5.4▾ SunlitJira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.
jira_align >= 11.14.0, < 11.16.1Upgrade past the affected range:
jira_align 11.16.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-22176Medium· 4.3Jira Align is vulnerable to an authorization issue
CVE-2025-22177Medium· 4.3Jira Align is vulnerable to an authorization issue
CVE-2025-22171Medium· 4.3Jira Align is vulnerable to an authorization issue
CVE-2025-22172Medium· 4.3Jira Align is vulnerable to an authorization issue
CVE-2025-22173Medium· 4.3Jira Align is vulnerable to an authorization issue
CVE-2025-22174Medium· 4.3Jira Align is vulnerable to an authorization issue