There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions
Published Aug 9, 2019 ·Due Sep 7, 2022
9.8
CRITICALCVSS 3.1
EPSS 84.62%
Description
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.
Affected products
-
- Version 4.4.0StatusaffectedConstraints<unspecified
- Version 7.7.0StatusaffectedConstraints<unspecified
- Version 8.0.0StatusaffectedConstraints<unspecified
- Version 8.1.0StatusaffectedConstraints<unspecified
- Version 8.2.0StatusaffectedConstraints<unspecified
- Version unspecifiedStatusaffectedConstraints<7.13.5
- Version unspecifiedStatusaffectedConstraints<7.6.14
- Version unspecifiedStatusaffectedConstraints<8.0.3
- Version unspecifiedStatusaffectedConstraints<8.1.2
- Version unspecifiedStatusaffectedConstraints<8.2.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Atlassian | Jira Server and Data Center | n/a |
|
- ≥ 4.4 · < 7.6.14
- ≥ 7.7.0 · < 7.13.5
- ≥ 8.0.0 · < 8.0.3
- ≥ 8.1.0 · < 8.1.2
- ≥ 8.2.0 · < 8.2.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://jira.atlassian.com/browse/JRASERVER-69532 x_refsource_MISCIssue TrackingVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11581 government-resourceUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://jira.atlassian.com/browse/JRASERVER-69532 | x_refsource_MISCIssue TrackingVendor Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11581 | government-resourceUS Government Resource |
Change history (0)
No recorded changes yet.