HTTP: Atlassian Jira Server And Data Center Email Templates Server-Side Template Injection

This signature detects attempts to exploit a known vulnerability against Atlassian Jira Server And Data Center. A successful attack can lead to arbitrary code execution.

Extended Description

This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. In this case the security improvement was to protect against using the XStream library to be able to execute arbitrary code in velocity templates. The affected versions are before version 8.13.19, from version 8.14.0 before 8.20.7, and from version 8.21.0 before 8.22.1.

Affected Products

Atlassian jira_server

Short Name
HTTP:CTS:ATLSSIN-JIRA-SR-DC-RCE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
And Atlassian CVE-2022-36799 Center Data Email Injection Jira Server Server-Side Template Templates
Release Date
03/14/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3669
False Positive
Unknown
Vendors

Atlassian

Found a potential security threat?