← back
CVE-2022-39960observed exploitation

CVE-2022-39960

45Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 26%
from disclosure to weapon
Published on NVDSep 17
VulnCheck+422d
exploitation probability
26%top 2% of all CVEs
observed exploitation
yesVulnCheck
The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all groups from the Jira instance by making a groupexport_download=true request to a plugins/servlet/groupexportforjira/admin/ URI.
Affected products
n/a · n/a