CVE-2019-15001
Summary
| CVE | CVE-2019-15001 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-19 15:15:00 UTC |
| Updated | 2022-04-22 19:53:00 UTC |
| Description | The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator permissions to gain remote code execution via a template injection vulnerability through the use of a crafted PUT request. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Atlassian | Jira | All | All | All | All |
| Application | Atlassian | Jira | 8.4.0 | All | All | All |
| Application | Atlassian | Jira | All | All | All | All |
| Application | Atlassian | Jira | 8.4.0 | All | All | All |
| Application | Atlassian | Jira Data Center | All | All | All | All |
| Application | Atlassian | Jira Data Center | 8.4.0 | All | All | All |
| Application | Atlassian | Jira Server | All | All | All | All |
| Application | Atlassian | Jira Server | 8.4.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Jira Server / Data Center Template Injection ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Bugtraq: Jira Security Advisory - 2019-09-18 - CVE-2019-15001 | BUGTRAQ | seclists.org | |
| [JRASERVER-69933] Template injection in Jira importers plugin - CVE-2019-15001 - Create and track feature requests for Atlassian products. | MISC | jira.atlassian.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.