Uploaded image for project: 'Jira Service Management Data Center'
  1. Jira Service Management Data Center
  2. JSDSERVER-16154

XXE (XML External Entity Injection) in Jira Service Management Data Center and Server

    • Icon: Public Security Vulnerability Public Security Vulnerability
    • Resolution: Fixed
    • Icon: High High
    • 5.12.22
    • 5.12.0, (20)
      5.12.1, 5.12.2, 5.13.1, 5.12.3, 5.12.4, 5.12.6, 5.12.5, 5.12.7, 5.12.8, 5.12.9, 5.12.12, 5.12.10, 5.12.11, 5.12.13, 5.12.14, 5.12.15, 5.12.16, 5.12.17, 5.12.18, 5.12.19
    • None
    • 7.7
    • High
    • CVE-2021-33813
    • Atlassian (Internal)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H
    • XXE (XML External Entity Injection)
    • Jira Service Management Data Center, Jira Service Management Server

      This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 5.12.0 of Jira Service Management Data Center and Server.

      This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.7, allows an attacker to access local and remote content.

      Atlassian recommends that Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:

      • Jira Service Management Data Center and Server 5.12: Upgrade to a release greater than or equal to 5.12.22

      See the release notes (https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html). You can download the latest version of Jira Service Management Data Center and Server from the download center (https://www.atlassian.com/software/jira/service-management/download-archives).

      This vulnerability was reported via our Atlassian (Internal) program.

          Form Name

            [JSDSERVER-16154] XXE (XML External Entity Injection) in Jira Service Management Data Center and Server

            Jose Filho made changes -
            Affects Version/s New: 5.13.1 [ 106533 ]
            prodsec-jac-bot made changes -
            Resolution New: Fixed [ 1 ]
            Security Original: Reporter and Atlassian Staff [ 10751 ]
            Status Original: Draft [ 12872 ] New: Published [ 12873 ]
            Yufei Zuo made changes -
            Affected Product(s) Original: Jira Core Data Center,Jira Core Server,Jira Software Server [ 18179, 18180, 18187 ] New: Jira Service Management Data Center,Jira Service Management Server [ 18183, 18184 ]
            Yufei Zuo made changes -
            Affects Version/s New: 5.12.1 [ 106162 ]
            Affects Version/s New: 5.12.2 [ 106520 ]
            Affects Version/s New: 5.12.3 [ 106541 ]
            Affects Version/s New: 5.12.4 [ 106912 ]
            Affects Version/s New: 5.12.6 [ 107322 ]
            Affects Version/s New: 5.12.5 [ 107330 ]
            Affects Version/s New: 5.12.7 [ 107622 ]
            Affects Version/s New: 5.12.8 [ 108111 ]
            Affects Version/s New: 5.12.9 [ 107820 ]
            Affects Version/s New: 5.12.12 [ 108392 ]
            Affects Version/s New: 5.12.10 [ 108205 ]
            Affects Version/s New: 5.12.11 [ 108498 ]
            Affects Version/s New: 5.12.13 [ 108709 ]
            Affects Version/s New: 5.12.14 [ 109025 ]
            Affects Version/s New: 5.12.15 [ 109303 ]
            Affects Version/s New: 5.12.16 [ 109218 ]
            Affects Version/s New: 5.12.17 [ 110203 ]
            Affects Version/s New: 5.12.18 [ 110204 ]
            Affects Version/s New: 5.12.19 [ 110205 ]
            Yufei Zuo made changes -
            Description Original: This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 5.12.19 of Jira Service Management Data Center and Server.

            This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.7, allows an attacker to access local and remote content.

            Atlassian recommends that Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
             * Jira Service Management Data Center and Server 5.12: Upgrade to a release greater than or equal to 5.12.22

            See the release notes ([https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html]). You can download the latest version of Jira Service Management Data Center and Server from the download center ([https://www.atlassian.com/software/jira/service-management/download-archives]).

            This vulnerability was reported via our Atlassian (Internal) program.
            New: This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 5.12.0 of Jira Service Management Data Center and Server.

            This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.7, allows an attacker to access local and remote content.

            Atlassian recommends that Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
             * Jira Service Management Data Center and Server 5.12: Upgrade to a release greater than or equal to 5.12.22

            See the release notes ([https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html]). You can download the latest version of Jira Service Management Data Center and Server from the download center ([https://www.atlassian.com/software/jira/service-management/download-archives]).

            This vulnerability was reported via our Atlassian (Internal) program.
            Yufei Zuo made changes -
            Affects Version/s Original: 5.12.19 [ 110205 ]
            Affects Version/s New: 5.12.0 [ 105722 ]
            Yufei Zuo made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 1007346 ]
            Yufei Zuo made changes -
            Description Original: This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 5.12.19 of Jira Service Management Data Center and Server.

            This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.7, allows an attacker to access local and remote content.

            Atlassian recommends that Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
             * Jira Service Management Data Center and Server 9.12: Upgrade to a release greater than or equal to 9.12.22

            See the release notes ([https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html]). You can download the latest version of Jira Service Management Data Center and Server from the download center ([https://www.atlassian.com/software/jira/service-management/download-archives]).

            This vulnerability was reported via our Atlassian (Internal) program.
            New: This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 5.12.19 of Jira Service Management Data Center and Server.

            This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.7, allows an attacker to access local and remote content.

            Atlassian recommends that Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
             * Jira Service Management Data Center and Server 5.12: Upgrade to a release greater than or equal to 5.12.22

            See the release notes ([https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html]). You can download the latest version of Jira Service Management Data Center and Server from the download center ([https://www.atlassian.com/software/jira/service-management/download-archives]).

            This vulnerability was reported via our Atlassian (Internal) program.
            Yufei Zuo made changes -
            Affects Version/s Original: 5.12.0 [ 105722 ]
            Affects Version/s New: 5.12.19 [ 110205 ]
            Yufei Zuo made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 1007143 ]

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: