We couldn't load all Actvitity tabs. Refresh the page to try again.
If the problem persists, contact your Jira admin.
IMPORTANT: JAC is a Public system and anyone on the internet will be able to view the data in the created JAC tickets. Please don’t include Customer or Sensitive data in the JAC ticket.
Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-75331

Malicious file upload in Jira Server via anonymous sources

    • 5.3
    • Medium

      Affected versions of Atlassian Jira Server/DC allows an unauthenticated attacker to upload arbitrary files to Jira via file upload functionality in the fileupload url. However An attacker cannot control the filename or its location, which prevents the possibility of RCE.

      Files with name start with multPartReq with .tmp filename may be seen in "<JIRA_INSTALL>/work" path location due to this bug.

      Affected versions:

      • version < 9.4.0
      • 9.4.0 < version < 9.4.3
      • version <= 8.20.18
      • version <= 8.13.27

      Fixed versions: 

      • 9.4.4
      • 8.20.20
      • 9.5.4

            IMPORTANT: JAC is a Public system and anyone on the internet will be able to view the data in the created JAC tickets. Please don’t include Customer or Sensitive data in the JAC ticket.
            Uploaded image for project: 'Jira Data Center'
            1. Jira Data Center
            2. JRASERVER-75331

            Malicious file upload in Jira Server via anonymous sources

              • 5.3
              • Medium

                Affected versions of Atlassian Jira Server/DC allows an unauthenticated attacker to upload arbitrary files to Jira via file upload functionality in the fileupload url. However An attacker cannot control the filename or its location, which prevents the possibility of RCE.

                Files with name start with multPartReq with .tmp filename may be seen in "<JIRA_INSTALL>/work" path location due to this bug.

                Affected versions:

                • version < 9.4.0
                • 9.4.0 < version < 9.4.3
                • version <= 8.20.18
                • version <= 8.13.27

                Fixed versions: 

                • 9.4.4
                • 8.20.20
                • 9.5.4

                        Unassigned Unassigned
                        security-metrics-bot Security Metrics Bot
                        0 Vote for this issue
                        6 Start watching this issue


                            Unassigned Unassigned
                            security-metrics-bot Security Metrics Bot
                            0 Vote for this issue
                            6 Start watching this issue
