Junglewise Threat Intelligence

CVE-2019-11581: Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability

CVE-2019-11581 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-07

Technologies: Atlassian Data Center. Vendors: Atlassian.

Executive brief

Atlassian Jira Server and Data Center are vulnerable to Server-Side Template Injection (SSTI) via the ContactAdministrators and SendBulkMail actions. A remote, unauthenticated attacker can exploit this to execute arbitrary code on the affected system.

Affected products

  • Atlassian Jira Server 4.4.0 to < 7.6.14, 7.7.0 to < 7.13.5, 8.0.0 to < 8.0.3, 8.1.0 to < 8.1.2, 8.2.0 to < 8.2.3
  • Atlassian Jira Data Center 4.4.0 to < 7.6.14, 7.7.0 to < 7.13.5, 8.0.0 to < 8.0.3, 8.1.0 to < 8.1.2, 8.2.0 to < 8.2.3

Timeline

  • 2019-08-19: disclosed: Initial analysis by NIST
  • 2022-03-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-07: exploited: Confirmed exploitation in the wild per CISA KEV entry

Related threats