Vulnerability Watch

Forum Discussion

snarang's avatar
snarang
Product Team
6 years ago

Server-Side Template Injection Vulnerability in Atlassian...

Server-Side Template Injection Vulnerability in Atlassian Jira Server and Data Center

On July 10, Atlassian published Security Advisory 2019-07-10 to address CVE-2019-11581, a critical server-side template injection vulnerability in “various resources” of Jira Server and Data Center, popular software to manage issue tracking used by many organizations around the world. The vulnerability could be exploited by an unauthenticated or authenticated attacker depending on the configuration settings for the vulnerable Jira system.

According to the advisory, the vulnerability was introduced in version 4.4.0, which was released in August 2011, making this vulnerability nearly eight years old.

To learn more, please visit our blog.

No RepliesBe the first to reply