QID 730148
Date Published: 2021-08-05
QID 730148: Atlassian Jira Remote code execution Vulnerability (JRASERVER-72660)
Jira is a proprietary issue tracking product, developed by Atlassian. It provides bug tracking, issue tracking, and project management functions.
Affected by below vulnerability:
CVE-2017-18113: Remote code execution in workflow import
Affected version:
Atlassian Jira Server versions prior to version 8.18.1
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Atlassian Jira.
Successful exploitation of this vulnerability may allows remote attackers who can trick a system administrator to import their malicious workflow to execute arbitrary code via a Remote Code Execution (RCE) vulnerability.
Solution
Customers are advised to refer JRASERVER-72660 for updates pertaining to this vulnerability.
Vendor References
- JRASERVER-72660 -
jira.atlassian.com/browse/JRASERVER-72660
CVEs related to QID 730148
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JRASERVER-72660 |
|