CVE-2019-10100: Code Injection
In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an Issue macro to the page in Confluence, and use a combination of a valid id field and specially crafted code in the link-text-template field to execute code remotely.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10100?
CVE-2019-10100 has been classified as a critical vulnerability due to the potential for Server Side Template Injection.
How do I fix CVE-2019-10100?
To mitigate CVE-2019-10100, upgrade the JetBrains YouTrack Confluence plugin to version 1.8.1.3 or later.
What impact does CVE-2019-10100 have on my system?
Exploitation of CVE-2019-10100 allows an attacker to execute arbitrary code on the server through specially crafted input.
Which versions of the JetBrains YouTrack Confluence plugin are affected by CVE-2019-10100?
CVE-2019-10100 affects all versions of the JetBrains YouTrack Confluence plugin prior to 1.8.1.3.
Who can exploit CVE-2019-10100?
Any authenticated user with the ability to add an Issue macro in Confluence can exploit CVE-2019-10100.