CVE-2008-6531: Code Injection
The WebWork 1 web application framework in Atlassian JIRA before 3.13.2 allows remote attackers to invoke exposed public JIRA methods via a crafted URL that is dynamically transformed into method calls, aka "WebWork 1 Parameter Injection Hole."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6531?
CVE-2008-6531 is considered a critical vulnerability due to its capability to allow remote code execution.
How do I fix CVE-2008-6531?
To fix CVE-2008-6531, upgrade Atlassian JIRA to version 3.13.2 or later.
What software versions are affected by CVE-2008-6531?
CVE-2008-6531 affects Atlassian JIRA versions before 3.13.2, including versions such as 3.2.2, 3.9, and 2.6.1.
What type of attack can exploit CVE-2008-6531?
CVE-2008-6531 can be exploited through parameter injection via crafted URLs, allowing attackers to invoke JIRA methods.
Is there a workaround for CVE-2008-6531 if I can't upgrade?
There is no official workaround for CVE-2008-6531; upgrading to the latest version is the recommended action.