CVE-2019-11581
Summary
| CVE | CVE-2019-11581 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-09 20:15:00 UTC |
| Updated | 2022-03-25 17:22:00 UTC |
| Description | There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability. |
Risk And Classification
EPSS: 0.846210000 probability, percentile 0.996800000 (date 2026-07-22)
CISA KEV: Listed on 2022-03-07; due 2022-09-07; ransomware use Unknown
Problem Types: CWE-74
CISA Known Exploited Vulnerability
| Vendor | Atlassian |
|---|---|
| Product | Jira Server and Data Center |
| Name | Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2019-11581 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [JRASERVER-69532] CVE-2019-11581 - Template injection in various resources - Create and track feature requests for Atlassian products. | MISC | jira.atlassian.com | Issue Tracking, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730117 Atlassian Jira Server Template Injection Vulnerability (JRASERVER-69532)