QID 150488

Date Published: 2022-03-17

QID 150488: Atlassian Jira Server Email Template Injection to RCE Vulnerability (JRASERVER-73067)

Jira is a proprietary issue tracking product, product developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.

The installed version of Jira Atlassian Server allow anonymous remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature.

Affected version:
before version 8.13.15
from version 8.14.0 before 8.20.3

QID Detection Logic:(Unauthenticated):
It checks for vulnerable version of Atlassian Jira Server.

Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the target system.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Upgrade the Atlassian Jira to new version.
    Vendor References

    CVEs related to QID 150488

    Software Advisories
    Advisory ID Software Component Link
    JRASERVER-73067 URL Logo jira.atlassian.com/browse/JRASERVER-73067