Jira Software Vulnerability Let Attacker Modify Any Filesystem Path Writable By JVM process
Atlassian has disclosed a high-severity path traversal vulnerability in Jira Software Data Center and Server. This vulnerability allows authenticated attackers to write files to any path accessible by the Java Virtual Machine (JVM) process.
Atlassian has disclosed a high-severity path traversal vulnerability in Jira Software Data Center and Server. This vulnerability allows authenticated attackers to write files to any path accessible by the Java Virtual Machine (JVM) process.
This flaw, identified as CVE-2025-22167 with a CVSS score of 8.7, affects versions from 9.12.0 to 11.0.1. It was internally discovered, leading to urgent recommendations for patching.
Organizations using Jira for project management are at risk of data tampering or service disruption if the vulnerability remains unpatched.
The vulnerability arises from inadequate input validation within file handling mechanisms, allowing low-privilege users, such as authenticated users, to bypass path restrictions.
By crafting specific requests, attackers can inject traversal sequences to access sensitive directories, writing data wherever the JVM has write permissions.
This issue was introduced in versions 9.12.0 and 10.3.0 and persisted into the 11.0 branch until fixes were implemented in versions 9.12.28, 10.3.12, and 11.1.0.
Atlassian has confirmed that no user interaction is required, and the attack vector is network-based with low complexity, making remote exploitation possible.
Atlassian has disclosed a high-severity path traversal vulnerability in Jira Software Data Center and Server.
While primarily an arbitrary write issue, it could enable data reads if combined with other vulnerabilities, potentially leading to data exfiltration or code injection.
For businesses using Jira in software development or IT operations, exploitation could corrupt configuration files, alter project data, or deploy malware, resulting in operational challenges or compliance issues.
High integrity and availability impacts mean attackers might delete logs, modify databases, or cause denial-of-service by overwriting critical files.
In regulated sectors, such as finance or healthcare, this could inadvertently expose intellectual property or sensitive information.
No public exploits are known yet, but the ease of access requiring only basic authentication increases urgency, particularly for internet-facing instances.
Atlassian recommends immediate upgrades to patched versions: 9.12.28 or later for the 9.x series, 10.3.12 or higher for 10.x, and 11.1.0 or beyond for the latest branch.
Users unable to fully update should apply these minimum fixes and monitor release notes for further details. Interim measures include restricting JVM filesystem permissions, segmenting network access, and enabling anomaly detection for file changes.
Regular backups and audits are essential to recover from potential incidents. Atlassian's proactive reporting emphasizes the importance of timely patching to prevent targeted attacks amidst prevalent supply chain threats.
With over 200,000 organizations relying on Jira, swift action is critical to safeguard workflows.
Based on reporting by Cyber Security News.
