CVE-2019-11581: Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.
Other sources
Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 7.6.14 - Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 7.13.5 - Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.0.3 - Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.1.2 - Upgrade
Upgrade
Atlassian Jira Server and Data Centerto a version that resolves this vulnerability.Fixed in 8.2.3
Event History
Frequently Asked Questions
What is CVE-2019-11581?
CVE-2019-11581 is a server-side template injection vulnerability in Atlassian Jira Server and Data Center.
How does CVE-2019-11581 affect Jira Server and Data Center?
CVE-2019-11581 allows an attacker to remotely execute code on systems running a vulnerable version of Jira Server or Data Center.
What is the severity of CVE-2019-11581?
CVE-2019-11581 has a severity score of 9.8, which is classified as critical.
Which versions of Jira Server and Data Center are affected by CVE-2019-11581?
CVE-2019-11581 affects all versions of Jira Server and Data Center ranging from 4.4 to 7.6.14, 7.7.0 to 7.13.5, 8.0.0 to 8.0.3, 8.1.0 to 8.1.2, and 8.2.0 to 8.2.3.
How can I fix the CVE-2019-11581 vulnerability in Jira Server and Data Center?
To fix the CVE-2019-11581 vulnerability, it is recommended to upgrade to the latest version of Jira Server or Data Center.