// For flags

CVE-2019-15001

 

Severity Score

7.2
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator permissions to gain remote code execution via a template injection vulnerability through the use of a crafted PUT request.

El plugin Jira Importers en Atlassian Jira Server y Data Cente desde la versión 7.0.10 anterior a 7.6.16, desde 7.7.0 anterior a 7.13.8, desde 8.0.0 anterior a 8.1.3, desde 8.2.0 anterior a 8.2.5, desde 8.3.0 anterior a 8.3.4 y desde 8.4.0 anteriores a 8.4.1, permite a atacantes remotos con permisos de Administrador conseguir la ejecución de código remota por medio de una vulnerabilidad de inyección de plantilla mediante el uso de una petición PUT diseñada

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-08-13 CVE Reserved
  • 2019-09-19 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Atlassian
Search vendor "Atlassian"
Jira Server
Search vendor "Atlassian" for product "Jira Server"
>= 7.0.10 < 7.6.16
Search vendor "Atlassian" for product "Jira Server" and version " >= 7.0.10 < 7.6.16"
-
Affected
Atlassian
Search vendor "Atlassian"
Jira Server
Search vendor "Atlassian" for product "Jira Server"
>= 7.7.0 < 7.13.8
Search vendor "Atlassian" for product "Jira Server" and version " >= 7.7.0 < 7.13.8"
-
Affected
Atlassian
Search vendor "Atlassian"
Jira Server
Search vendor "Atlassian" for product "Jira Server"
>= 8.0.0 < 8.1.3
Search vendor "Atlassian" for product "Jira Server" and version " >= 8.0.0 < 8.1.3"
-
Affected
Atlassian
Search vendor "Atlassian"
Jira Server
Search vendor "Atlassian" for product "Jira Server"
>= 8.2.0 < 8.2.5
Search vendor "Atlassian" for product "Jira Server" and version " >= 8.2.0 < 8.2.5"
-
Affected
Atlassian
Search vendor "Atlassian"
Jira Server
Search vendor "Atlassian" for product "Jira Server"
>= 8.3.0 < 8.3.4
Search vendor "Atlassian" for product "Jira Server" and version " >= 8.3.0 < 8.3.4"
-
Affected
Atlassian
Search vendor "Atlassian"
Jira Server
Search vendor "Atlassian" for product "Jira Server"
8.4.0
Search vendor "Atlassian" for product "Jira Server" and version "8.4.0"
-
Affected
Atlassian
Search vendor "Atlassian"
Jira Data Center
Search vendor "Atlassian" for product "Jira Data Center"
>= 7.0.10 < 7.6.16
Search vendor "Atlassian" for product "Jira Data Center" and version " >= 7.0.10 < 7.6.16"
-
Affected
Atlassian
Search vendor "Atlassian"
Jira Data Center
Search vendor "Atlassian" for product "Jira Data Center"
>= 7.7.0 < 7.13.8
Search vendor "Atlassian" for product "Jira Data Center" and version " >= 7.7.0 < 7.13.8"
-
Affected
Atlassian
Search vendor "Atlassian"
Jira Data Center
Search vendor "Atlassian" for product "Jira Data Center"
>= 8.0.0 < 8.1.3
Search vendor "Atlassian" for product "Jira Data Center" and version " >= 8.0.0 < 8.1.3"
-
Affected
Atlassian
Search vendor "Atlassian"
Jira Data Center
Search vendor "Atlassian" for product "Jira Data Center"
>= 8.2.0 < 8.2.5
Search vendor "Atlassian" for product "Jira Data Center" and version " >= 8.2.0 < 8.2.5"
-
Affected
Atlassian
Search vendor "Atlassian"
Jira Data Center
Search vendor "Atlassian" for product "Jira Data Center"
>= 8.3.0 < 8.3.4
Search vendor "Atlassian" for product "Jira Data Center" and version " >= 8.3.0 < 8.3.4"
-
Affected
Atlassian
Search vendor "Atlassian"
Jira Data Center
Search vendor "Atlassian" for product "Jira Data Center"
8.4.0
Search vendor "Atlassian" for product "Jira Data Center" and version "8.4.0"
-
Affected