CVE-2019-15001
The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.4%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator permissions to gain remote code execution via a template injection vulnerability through the use of a crafted PUT request.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 11.37% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- atlassian/jira server · atlassian/jira data center
- Source
- security@atlassian.com
References
- http://packetstormsecurity.com/files/154611/Jira-Server-Data-Center-Template-Injection.htmlThird Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/JRASERVER-69933Release Notes, Vendor Advisory
- https://seclists.org/bugtraq/2019/Sep/42Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/154611/Jira-Server-Data-Center-Template-Injection.htmlThird Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/JRASERVER-69933Release Notes, Vendor Advisory
- https://seclists.org/bugtraq/2019/Sep/42Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.