CVE-2019-11581 Information
Feb 14, 2021
cve
Description
There was a server-side template injection vulnerability in Jira Server and Data Center in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14 from 7.7.0 before 7.13.5 from 8.0.0 before 8.0.3 from 8.1.0 before 8.1.2 and from 8.2.0 before 8.2.3 are affected by this vulnerability.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://jira.atlassian.com/browse/JRASERVER-69532
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: