VYPR
Unrated severityNVD Advisory· Published Jul 3, 2019· Updated Aug 4, 2024

CVE-2019-10100

CVE-2019-10100

Description

JetBrains YouTrack Confluence plugin before 1.8.1.3 is vulnerable to SSTI via Issue macro link-text-template field, enabling remote code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

JetBrains YouTrack Confluence plugin before 1.8.1.3 is vulnerable to SSTI via Issue macro link-text-template field, enabling remote code execution.

Vulnerability

The JetBrains YouTrack Confluence plugin versions prior to 1.8.1.3 contain a Server-Side Template Injection (SSTI) vulnerability. An attacker with the ability to add an Issue macro to a Confluence page can inject malicious template code through the link-text-template field, while providing a valid id field to reach the vulnerable code path [1].

Exploitation

The attacker must have the ability to create or edit a Confluence page containing the Issue macro. The exploit requires only a valid issue ID and a specially crafted payload in the link-text-template field. No authentication beyond standard Confluence page editing privileges is needed. The attacker supplies a malicious template string in the link-text-template parameter, which is then processed by the server-side template engine without proper sanitization [1].

Impact

Successful exploitation allows the attacker to achieve remote code execution on the Confluence server. This leads to full compromise of the application server, including potential access to sensitive data, modification of configurations, and further lateral movement within the infrastructure [1].

Mitigation

The vulnerability is fixed in YouTrack Confluence plugin version 1.8.1.3, released as part of the JetBrains Q1 2019 security bulletin. Users should upgrade to this version or later. No workaround is documented; the only mitigation is to apply the update [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.