CVE-2019-15001

The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator permissions to gain remote code execution via a template injection vulnerability through the use of a crafted PUT request.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
atlassianCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
Affected Products (NVD)
VendorProductVersion
atlassianjira_server
7.0.10 ≤
𝑥
< 7.6.16
atlassianjira_server
7.7.0 ≤
𝑥
< 7.13.8
atlassianjira_server
8.0.0 ≤
𝑥
< 8.1.3
atlassianjira_server
8.2.0 ≤
𝑥
< 8.2.5
atlassianjira_server
8.3.0 ≤
𝑥
< 8.3.4
atlassianjira_server
8.4.0
atlassianjira_data_center
7.0.10 ≤
𝑥
< 7.6.16
atlassianjira_data_center
7.7.0 ≤
𝑥
< 7.13.8
atlassianjira_data_center
8.0.0 ≤
𝑥
< 8.1.3
atlassianjira_data_center
8.2.0 ≤
𝑥
< 8.2.5
atlassianjira_data_center
8.3.0 ≤
𝑥
< 8.3.4
atlassianjira_data_center
8.4.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
atlassianjira
7.0.10
CNA
atlassianjira
𝑥
< 7.6.16
CNA
atlassianjira
7.7.0
CNA
atlassianjira
𝑥
< 7.13.8
CNA
atlassianjira
8.0.0
CNA
atlassianjira
𝑥
< 8.1.3
CNA
atlassianjira
8.2.0
CNA
atlassianjira
𝑥
< 8.2.5
CNA
atlassianjira
8.3.0
CNA
atlassianjira
𝑥
< 8.3.4
CNA
atlassianjira
8.4.0
CNA
atlassianjira
𝑥
< 8.4.1
CNA