Impact
Caller-supplied"projects_filter" and "spaces_filter" parameters in the MCP Atlassian server can override administrator‑configured allowlists, allowing an attacker to query Jira or Confluence projects and spaces beyond the intended access boundaries. This bypass enables the retrieval of data that the supplied Atlassian credentials normally cannot access, effectively granting unauthorized data exposure. The underlying weakness is an access control flaw (CWE‑284), where filtering logic fails to enforce the configured restrictions.
Affected Systems
The vulnerability affects deployments of sooperset’s MCP Atlassian server versions prior to 0.22.0. Users running this software with remote or local access to the search APIs on Confluence and Jira can exploit the flaw. The fix is delivered in release v0.22.0 and later.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is the API that accepts the filter parameters; an attacker who can submit requests to the server can provide crafted filter clauses to gain access to restricted projects or spaces. Identifying suitable Atlassian credentials that have the necessary permissions is a prerequisite for exploitation, but once those credentials exist the bypass removes the need for additional privileges.
OpenCVE Enrichment