CVE-2019-11581
KEVlargeUnauthenticated SSTI RCE in Atlassian Jira Server and Data Center
CISA: Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability
Atlassian Jira Server and Data Center contain a server-side template injection (CWE-74) in the ContactAdministrators and SendBulkMail actions, rated critical at CVSS 9.8. The flaw is triggered by sending crafted, template-syntax input to these mail-related actions over the network; because the vulnerability requires no authentication or user interaction per the CVSS vector, any attacker who can reach the Jira web interface can trigger it. Successful exploitation yields unauthenticated remote code execution on the server hosting Jira, with high impact on confidentiality, integrity, and availability. Organizations running any Jira Server or Data Center release in the 4.4–7.6, 7.7–7.13, 8.0, 8.1, or 8.2 lines prior to the listed fixed versions are affected, and the exposure is concentrated among instances reachable from the internet. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07 with a required action to apply vendor updates, and EPSS places it in the 100th percentile (~84.6% probability of exploitation within 30 days).
What to do: Apply the vendor updates per Atlassian/CISA instructions — upgrade to Jira 7.6.14, 7.13.5, 8.0.3, 8.1.2, or 8.2.3 (or later) as applicable, since this is a KEV item with a required patching action. As an interim mitigation, disable the 'Allow users to contact administrators' option in Jira's General Configuration to close the ContactAdministrators path and restrict SendBulkMail access, and limit exposure of the Jira web interface to the internet. Review access logs for requests hitting ContactAdministrators/SendBulkMail endpoints containing template injection payloads and hunt for signs of post-exploitation code execution on affected servers.
| Atlassian Jira Server | All versions from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 |
| Atlassian Jira Data Center | All versions from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.
- Affected
- Atlassian Jira Server and Data Center
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- atlassian
- Products
- jira server
- Weakness
- CWE-74
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H