← All CVEs

CVE-2019-11581

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-07Remediation due 2022-09-07

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.

9.8
CVSS
84.6%
EPSS (exploit prob.)
100th
EPSS percentile
2019-08-09
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-74

Affected products

VendorProductAffected versions
atlassianjira_server>= 4.4, < 7.6.14
atlassianjira_server>= 7.7.0, < 7.13.5
atlassianjira_server>= 8.0.0, < 8.0.3
atlassianjira_server>= 8.1.0, < 8.1.2
atlassianjira_server>= 8.2.0, < 8.2.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-11581