CVE-2017-5983
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 16.37% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- atlassian/jira
- Source
- cve@mitre.org
References
- http://codewhitesec.blogspot.com/2017/04/amf.htmlTechnical Description
- http://www.securityfocus.com/bid/97379Third Party Advisory, VDB Entry
- https://confluence.atlassian.com/jira063/jira-security-advisory-2017-03-09-875604401.htmlVendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-64077Vendor Advisory
- https://www.kb.cert.org/vuls/id/307983Third Party Advisory, US Government Resource, VDB Entry
- http://codewhitesec.blogspot.com/2017/04/amf.htmlTechnical Description
- http://www.securityfocus.com/bid/97379Third Party Advisory, VDB Entry
- https://confluence.atlassian.com/jira063/jira-security-advisory-2017-03-09-875604401.htmlVendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-64077Vendor Advisory
- https://www.kb.cert.org/vuls/id/307983Third Party Advisory, US Government Resource, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.