QID 150466
Date Published: 2022-02-07
QID 150466: Atlassian Jira Server Template Injection Vulnerability (JRASERVER-72804)
Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
The installed version of Jira Atlassian Server using the Jira Service Management addon allow remote attackers with JIRA Administrators access to execute arbitrary Java code via a server-side template injection vulnerability in the Email Template feature.
Affected version:
before version 8.13.12
from version 8.14.0 before 8.19.1
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code.
Solution
Upgrade the Atlassian Jira to new version.
Vendor References
- JRASERVER-72804 -
jira.atlassian.com/browse/JRASERVER-72804
CVEs related to QID 150466
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72804 |
|