CVE-2019-11581
Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 7 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 84.62% probability · 100th percentile
- CISA KEV
- Listed 7 March 2022 · due 7 September 2022
- Weakness
- CWE-74
- Affected
- atlassian/jira server
- Source
- security@atlassian.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-11581
References
- https://jira.atlassian.com/browse/JRASERVER-69532Issue Tracking, Vendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-69532Issue Tracking, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11581US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.