CVE-2022-36799
Description
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. In this case the security improvement was to protect against using the XStream library to be able to execute arbitrary code in velocity templates. The affected versions are before version 8.13.19, from version 8.14.0 before 8.20.7, and from version 8.21.0 before 8.22.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*range: <8.13.19
- (no CPE)range: unspecified
- Range: <8.13.19, 8.14.0 to <8.20.7, 8.21.0 to <8.22.1
- Range: unspecified
Patches
Vulnerability mechanics
References
1- jira.atlassian.com/browse/JRASERVER-73582nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.