SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-36799

Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature.

HIGH 7.2EPSS 45.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 45.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. In this case the security improvement was to protect against using the XStream library to be able to execute arbitrary code in velocity templates. The affected versions are before version 8.13.19, from version 8.14.0 before 8.20.7, and from version 8.21.0 before 8.22.1.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
45.28% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
atlassian/jira data center · atlassian/jira server
Source
security@atlassian.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.