CVE-2019-11581
CRITICALThere was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.
Affected Products
jira serveratlassianResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
There was a server-side template injection vulnerability in Jira Server …
There was a server-side template injection vulnerability in Jira Server …
There was a server-side template injection vulnerability in Jira Server …
There was a server-side template injection vulnerability in Jira Server …
There was a server-side template injection vulnerability in Jira Server …
There was a server-side template injection vulnerability in Jira Server …
Frequently Asked Questions
Is CVE-2019-11581 in your stack?
O3 detects CVE-2019-11581 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.