CVE-2022-36799
Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 45.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. In this case the security improvement was to protect against using the XStream library to be able to execute arbitrary code in velocity templates. The affected versions are before version 8.13.19, from version 8.14.0 before 8.20.7, and from version 8.21.0 before 8.22.1.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 45.28% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- atlassian/jira data center · atlassian/jira server
- Source
- security@atlassian.com
References
- https://jira.atlassian.com/browse/JRASERVER-73582Issue Tracking, Vendor Advisory
- https://jira.atlassian.com/browse/JRASERVER-73582Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.