CVE-2019-15001

The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator permissions to gain remote code execution via a template injection vulnerability through the use of a crafted PUT request.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
atlassianCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
atlassianjira_server
7.0.10 ≤
𝑥
< 7.6.16
atlassianjira_server
7.7.0 ≤
𝑥
< 7.13.8
atlassianjira_server
8.0.0 ≤
𝑥
< 8.1.3
atlassianjira_server
8.2.0 ≤
𝑥
< 8.2.5
atlassianjira_server
8.3.0 ≤
𝑥
< 8.3.4
atlassianjira_server
8.4.0
atlassianjira_data_center
7.0.10 ≤
𝑥
< 7.6.16
atlassianjira_data_center
7.7.0 ≤
𝑥
< 7.13.8
atlassianjira_data_center
8.0.0 ≤
𝑥
< 8.1.3
atlassianjira_data_center
8.2.0 ≤
𝑥
< 8.2.5
atlassianjira_data_center
8.3.0 ≤
𝑥
< 8.3.4
atlassianjira_data_center
8.4.0
𝑥
= Vulnerable software versions