SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2019-11581

Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability

KEVCRITICAL 9.8EPSS 84.6%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 7 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
84.62% probability · 100th percentile
CISA KEV
Listed 7 March 2022 · due 7 September 2022
Weakness
CWE-74
Affected
atlassian/jira server
Source
security@atlassian.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-11581

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.