CVE-2010-1165
Summary
| CVE | CVE-2010-1165 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-04-20 15:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Atlassian JIRA 3.12 through 4.1 allows remote authenticated administrators to execute arbitrary code by modifying the (1) attachment (aka attachments), (2) index (aka indexing), or (3) backup path and then uploading a file, as exploited in the wild in April 2010. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Atlassian | Jira | 3.12 | All | All | All |
| Application | Atlassian | Jira | 3.12.1 | All | All | All |
| Application | Atlassian | Jira | 3.12.2 | All | All | All |
| Application | Atlassian | Jira | 3.12.3 | All | All | All |
| Application | Atlassian | Jira | 3.13 | All | All | All |
| Application | Atlassian | Jira | 3.13.1 | All | All | All |
| Application | Atlassian | Jira | 3.13.2 | All | All | All |
| Application | Atlassian | Jira | 3.13.3 | All | All | All |
| Application | Atlassian | Jira | 3.13.4 | All | All | All |
| Application | Atlassian | Jira | 3.13.5 | All | All | All |
| Application | Atlassian | Jira | 4.0 | All | All | All |
| Application | Atlassian | Jira | 4.0.1 | All | All | All |
| Application | Atlassian | Jira | 4.0.2 | All | All | All |
| Application | Atlassian | Jira | 4.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Atlassian JIRA Multiple Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| JIRA Security Advisory 2010-04-16 - JIRA 4.2 - Atlassian Documentation - Confluence | af854a3a-2127-422b-91ae-364da2661108 | confluence.atlassian.com | Patch, Vendor Advisory |
| oss-security - CVE Request: JIRA Issues | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| oss-security - Re: CVE Request: JIRA Issues | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| [#JRA-20995] Privilege escalation vulnerability when administrator access is compromised - Atlassian JIRA | af854a3a-2127-422b-91ae-364da2661108 | jira.atlassian.com | Vendor Advisory |
| Atlassian JIRA Privilege Escalation and Multiple Cross Site Scripting Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [#JRA-21004] XSS and Privilege Escalation Vulnerabilities in JIRA - Atlassian JIRA | af854a3a-2127-422b-91ae-364da2661108 | jira.atlassian.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.