Executive brief
Atlassian Jira Server and Data Center are vulnerable to Server-Side Template Injection (SSTI) via the ContactAdministrators and SendBulkMail actions. A remote, unauthenticated attacker can exploit this to execute arbitrary code on the affected system.
Affected products
- Atlassian Jira Server 4.4.0 to < 7.6.14, 7.7.0 to < 7.13.5, 8.0.0 to < 8.0.3, 8.1.0 to < 8.1.2, 8.2.0 to < 8.2.3
- Atlassian Jira Data Center 4.4.0 to < 7.6.14, 7.7.0 to < 7.13.5, 8.0.0 to < 8.0.3, 8.1.0 to < 8.1.2, 8.2.0 to < 8.2.3
Timeline
- 2019-08-19: disclosed: Initial analysis by NIST
- 2022-03-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-07: exploited: Confirmed exploitation in the wild per CISA KEV entry