Impact
Atlassian Jira Service Management Data Center introduced an Improper Authorization flaw in version 11.3.0 that permits an authenticated user to access data or functions beyond the user’s intended privileges. The vulnerability can expose sensitive information or allow the attacker to execute commands when the exposed functionality supports arbitrary code execution-285, which means the application failed to enforce sufficient authorization checks on protected resources.
Affected Systems
The affected product is Atlassian Jira Service Management Data Center, specifically any deployment of version 11.3.0 through 11.3.10. Versions 11.3.11 and later include the remediation. Customers running the younger release should plan to upgrade to the current version suite available from the Atlassian download center.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level, while the EPSS score is < 1% and the vulnerability is not recorded in CISA's KEV catalog authenticated within the system; once authenticated, the elevated access can provide a wide attack surface. Given the EPSS score of < 1%, the probability of exploitation is low but the impact remains significant for organizations that have not applied the available patch.
OpenCVE Enrichment