Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-73582

Template Injection in Email Templates - bypass of mitigation via XStream - CVE-2022-36799

    • 7.2
    • High
    • CVE-2022-36799

      This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented.

      Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. In this case the security improvement was to protect against using the XStream library to be able to execute arbitrary code from velocity templates.

      Affected versions are before version 8.13.19, from version 8.14.0 before 8.20.7, and from version 8.21.0 before 8.22.1

      Affected versions:

      • version < 8.13.19
      • 8.14.0 ≤ version < 8.20.7
      • 8.21.0 ≤ version < 8.22.1

      Fixed versions:

      • 8.13.19
      • 8.20.7
      • 8.22.1

            [JRASERVER-73582] Template Injection in Email Templates - bypass of mitigation via XStream - CVE-2022-36799

            Cathy S made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 673458 ]
            Cathy S made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 671202 ]
            Security Metrics Bot made changes -
            CVE ID New: CVE-2022-36799
            David Black made changes -
            Description Original: This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented.

            Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. In this case the security improvement was to protect against using the XStream library to be able to execute arbitrary code from velocity templates.

            Affected versions are before version 8.13.19, from version 8.14.0 before 8.20.7, and from version 8.21.0 before 8.22.1

            *Affected versions:*
             * version < 8.13.19
             * 8.14.0 ≤ version < 8.20.7
             * 8.21.0 ≤ version < 8.22.1

            *Fixed versions:*
             * 8.13.15
             * 8.20.7
             * 8.22.1
            New: This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented.

            Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. In this case the security improvement was to protect against using the XStream library to be able to execute arbitrary code from velocity templates.

            Affected versions are before version 8.13.19, from version 8.14.0 before 8.20.7, and from version 8.21.0 before 8.22.1

            *Affected versions:*
             * version < 8.13.19
             * 8.14.0 ≤ version < 8.20.7
             * 8.21.0 ≤ version < 8.22.1

            *Fixed versions:*
             * 8.13.19
             * 8.20.7
             * 8.22.1
            David Black made changes -
            Labels Original: CVE-2022-36799 advisory advisory-to-release dont-import security 🔢✅ New: CVE-2022-36799 advisory advisory-released dont-import security 🔢✅
            David Black made changes -
            Security Original: Atlassian Staff [ 10750 ]
            David Black made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Draft [ 12872 ] New: Published [ 12873 ]
            David Black made changes -
            Labels Original: advisory advisory-to-release dont-import security 🔢✅ New: CVE-2022-36799 advisory advisory-to-release dont-import security 🔢✅
            David Black made changes -
            Summary Original: Template Injection in Email Templates - bypass of mitigation via XStream New: Template Injection in Email Templates - bypass of mitigation via XStream - CVE-2022-36799
            David Black made changes -
            Summary Original: Template Injection in Email Templates leads to code execution - bypass of mitigation via XStream New: Template Injection in Email Templates - bypass of mitigation via XStream

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: