RULE(RULE ID:323008)

Rule General Information
Release Date: 2019-07-15
Rule Name: Atlassian JIRA Template Injection Remote Code Execution Vulnerability (CVE-2019-11581)
Severity:
CVE ID:
Rule Protection Details
Description: There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Others
Reference: https://jira.atlassian.com/browse/JRASERVER-69532
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://confluence.atlassian.com/jira/jira-security-advisory-2019-07-10-973486595.html