Atlassian JIRA Data Center是澳大利亚Atlassian公司的Atlassian JIRA的数据中心版本。 Atlassian JIRA Server和JIRA Data Center中存在注入漏洞。攻击者可利用该漏洞执行任意代码或造成拒绝服务。以下产品及版本受到影响:Atlassian JIRA Server 4.4.x版本,5.x.x版本,6.x.x版本,7.0.x版本,7.1.x版本,7.2.x版本,7.3.x版本,7.4.x版本,7.5.x版本,7.6.14之前的7.6.x
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Atlassian | Jira Server and Data Center | 4.4.0 ~ unspecified | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Atlassian JIRA Template injection vulnerability RCE | https://github.com/jas502n/CVE-2019-11581 | POC Details |
| 2 | CVE-2019–11581 PoC | https://github.com/kobs0N/CVE-2019-11581 | POC Details |
| 3 | Atlassian Jira unauthen template injection | https://github.com/PetrusViet/CVE-2019-11581 | POC Details |
| 4 | Jira Server and Data Center is susceptible to a server-side template injection vulnerability via the ContactAdministrators and SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-11581.yaml | POC Details |
| 5 | None | https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Atlassian%20Jira%20%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%20CVE-2019-11581.md | POC Details |
| 6 | https://github.com/vulhub/vulhub/blob/master/jira/CVE-2019-11581/README.md | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-20826 | Atlassian Jira 授权问题漏洞 | |
| CVE-2018-20827 | Atlassian Jira 跨站脚本漏洞 |
No comments yet