$attachmentsManager.inlineImages($textParagraph) on notifications due security restrictions when using potential path traversal

XMLWordPrintable

    • Type: Bug
    • Resolution: Unresolved
    • Priority: Low
    • None
    • Affects Version/s: 10.0.0, 10.3.15
    • Component/s: Email notifications
    • None
    • 10
    • 5
    • Severity 2 - Major
    • 19

      Issue Summary

      When the string ../ is placed in the issue Description field, the body of the email notification is replaced with a large exception text and stack trace. When it is placed in a comment, the comment is replaced by the string $attachmentsManager.inlineImages($textParagraph)

      We suspect this is caused by the changes made in Jira 10 to velocity templates

      This behaviour is problematic because:

      • The content of the updated field is not normally displayed, and, 
      • If the string is being redacted for security reasons, the way it's being presented to the user presents as a bug, not a deliberate sanitation

      Steps to Reproduce

      1. Jira v10.3.15
      2. Integrate with an outbound mail server
      3. Disable Batching email notifications
      4. Create an issue
      5. Edit the issue's Description, adding the offending string
      6. Receive the update notification in your email client

      Expected Results

      The email content is sent verbatim

      At the very least, if the offending characters are not permitted, simply replace only those characters with an empty string. 

      Actual Results

      If the action was to add the offending string, the email body is mostly replaced with the following content:

       An error occurred whilst rendering this message. Please contact the administrators, and inform them of this bug. Details: ------- org.apache.velocity.exception.MethodInvocationException: Invocation of method 'diff' in class com.atlassian.jira.mail.DiffUtils threw exception java.lang.NullPointerException: Cannot invoke "String.length()" because "newText" is null at templates/email/html/includes/changelog-issue-description.vm[line 12, column 39] at org.apache.velocity.runtime.parser.node.ASTMethod.handleInvocationException(ASTMethod.java:342) at org.apache.velocity.runtime.parser.node.ASTMethod.execute(ASTMethod.java:284) at org.apache.velocity.runtime.parser.node.ASTReference.execute(ASTReference.java:262) at org.apache.velocity.runtime.parser.node.ASTReference.value(ASTReference.java:507) at org.apache.velocity.runtime.parser.node.ASTExpression.value(ASTExpression.java:71) at org.apache.velocity.runtime.parser.node.ASTSetDirective.render(ASTSetDirective.java:142) at org.apache.velocity.runtime.parser.node.ASTBlock.render(ASTBlock.java:72) at org.apache.velocity.runtime.parser.node.ASTIfStatement.render(ASTIfStatement.java:87) <SNIP>

      If the action was to remove the offending string, the email body is mostly replaced with the following content:

      An error occurred whilst rendering this message. Please contact the administrators, and inform them of this bug. Details: ------- org.apache.velocity.exception.MethodInvocationException: Invocation of method 'diff' in class com.atlassian.jira.mail.DiffUtils threw exception java.lang.NullPointerException: Cannot invoke "String.length()" because "oldText" is null at templates/email/html/includes/changelog-issue-description.vm[line 12, column 39] at org.apache.velocity.runtime.parser.node.ASTMethod.handleInvocationException(ASTMethod.java:342) at org.apache.velocity.runtime.parser.node.ASTMethod.execute(ASTMethod.java:284) at org.apache.velocity.runtime.parser.node.ASTReference.execute(ASTReference.java:262) at org.apache.velocity.runtime.parser.node.ASTReference.value(ASTReference.java:507) at org.apache.velocity.runtime.parser.node.ASTExpression.value(ASTExpression.java:71) at org.apache.velocity.runtime.parser.node.ASTSetDirective.render(ASTSetDirective.java:142) at org.apache.velocity.runtime.parser.node.ASTBlock.render(ASTBlock.java:72) at org.apache.velocity.runtime.parser.node.ASTIfStatement.render(ASTIfStatement.java:87) at org.apache.velocity.runtime.parser.node.SimpleNode.render(SimpleNode.java:336) at org.apache.velocity.runtime.directive.Parse.render(Parse.java:263) at org.apache.velocity.runtime.parser.node.ASTDirective.render(ASTDirective.java:175) at org.apache.velocity.runtime.parser.node.SimpleNode.render(SimpleNode.java:336) at org.apache.velocity.runtime.RuntimeInstance.render(RuntimeInstance.java:1267) at org.apache.velocity.runtime.RuntimeInstance.evaluate(RuntimeInstance.java:1206) at org.apache.velocity.runtime.RuntimeInstance.evaluate(RuntimeInstance.java:1155) at org.apache.velocity.app.VelocityEngine.evaluate(VelocityEngine.java:219)  <SNIP>

      If an image is present in the description, then the content will be as follows:

      An error occurred whilst rendering this message. Please contact the administrators, and inform them of this bug. Details: ------- org.apache.velocity.exception.MethodInvocationException: Invocation of method 'inlineImages' in class com.atlassian.jira.mail.util.MailAttachmentsManagerImpl threw exception java.lang.NullPointerException: Cannot invoke "java.lang.CharSequence.length()" because "this.text" is null at templates/email/html/includes/patterns/text-paragraph.vm[line 4, column 33] at org.apache.velocity.runtime.parser.node.ASTMethod.handleInvocationException(ASTMethod.java:342) at org.apache.velocity.runtime.parser.node.ASTMethod.execute(ASTMethod.java:284) at org.apache.velocity.runtime.parser.node.ASTReference.execute(ASTReference.java:262) at org.apache.velocity.runtime.parser.node.ASTReference.render(ASTReference.java:342) at org.apache.velocity.runtime.parser.node.SimpleNode.render(SimpleNode.java:336) at org.apache.velocity.runtime.directive.Parse.render(Parse.java:263) at org.apache.velocity.runtime.parser.node.ASTDirective.render(ASTDirective.java:175 

      Furthermore, the error is logged to the application logs:

      Mail Queue Service [velocity] Found a potential path traversal attempt in the parameters: [<p style='margin-top:0;margin-bottom:10px;'>...\DB</p>] of method: inlineImages from object of class: com.atlassian.jira.mail.util.MailAttachmentsManagerImpl, rejecting due to security restrictions  

      Here is how the user is presented with the update:

      Workaround

      Currently there is no known workaround for this behavior. A workaround will be added here when available

        1. image-2026-05-08-16-22-41-716.png
          1.07 MB
          Alex [Atlassian,PSE]

              Assignee:
              Unassigned
              Reporter:
              Mikaela Teixeira
              Votes:
              5 Vote for this issue
              Watchers:
              10 Start watching this issue

                Created:
                Updated: