Uploaded image for project: 'Jira Service Management Data Center'
  1. Jira Service Management Data Center
  2. JSDSERVER-16154

XXE (XML External Entity Injection) in Jira Service Management Data Center and Server

    • Icon: Public Security Vulnerability Public Security Vulnerability
    • Resolution: Fixed
    • Icon: High High
    • 5.12.22
    • 5.12.0, (20)
      5.12.1, 5.12.2, 5.13.1, 5.12.3, 5.12.4, 5.12.6, 5.12.5, 5.12.7, 5.12.8, 5.12.9, 5.12.12, 5.12.10, 5.12.11, 5.12.13, 5.12.14, 5.12.15, 5.12.16, 5.12.17, 5.12.18, 5.12.19
    • None
    • 7.7
    • High
    • CVE-2021-33813
    • Atlassian (Internal)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H
    • XXE (XML External Entity Injection)
    • Jira Service Management Data Center, Jira Service Management Server

      This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 5.12.0 of Jira Service Management Data Center and Server.

      This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.7, allows an attacker to access local and remote content.

      Atlassian recommends that Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:

      • Jira Service Management Data Center and Server 5.12: Upgrade to a release greater than or equal to 5.12.22

      See the release notes (https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html). You can download the latest version of Jira Service Management Data Center and Server from the download center (https://www.atlassian.com/software/jira/service-management/download-archives).

      This vulnerability was reported via our Atlassian (Internal) program.

            [JSDSERVER-16154] XXE (XML External Entity Injection) in Jira Service Management Data Center and Server

            Can you confirm if other versions of JSM are impacted ? EX. 5.17.5 ?

            This page states only 5.12.* is affected. 

            But when I look into April month's Security Bulletin link, it states, 5.17., 5.16. and many other branches as also affected for this CVE as well as for another CVE-2024-57699. 

            Link: https://confluence.atlassian.com/security/security-bulletin-april-15-2025-1540723536.html 

            Deleted Account (Inactive) added a comment - Can you confirm if other versions of JSM are impacted ? EX. 5.17.5 ? This page states only 5.12.* is affected.  But when I look into April month's Security Bulletin link, it states, 5.17. , 5.16. and many other branches as also affected for this CVE as well as for another CVE-2024-57699.  Link: https://confluence.atlassian.com/security/security-bulletin-april-15-2025-1540723536.html  
            Jose Filho made changes -
            Affects Version/s New: 5.13.1 [ 106533 ]

            Can you please elaborate on what you mean by "allows an attacker to access local and remote content"? The CVE you have linked to from the security bulletin for this vulnerability only says "An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request." 

            John Smith added a comment - Can you please elaborate on what you mean by "allows an attacker to access local and remote content"? The CVE you have linked to from the security bulletin for this vulnerability only says "An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request." 
            prodsec-jac-bot made changes -
            Resolution New: Fixed [ 1 ]
            Security Original: Reporter and Atlassian Staff [ 10751 ]
            Status Original: Draft [ 12872 ] New: Published [ 12873 ]
            Yufei Zuo made changes -
            Affected Product(s) Original: Jira Core Data Center,Jira Core Server,Jira Software Server [ 18179, 18180, 18187 ] New: Jira Service Management Data Center,Jira Service Management Server [ 18183, 18184 ]
            Yufei Zuo made changes -
            Affects Version/s New: 5.12.1 [ 106162 ]
            Affects Version/s New: 5.12.2 [ 106520 ]
            Affects Version/s New: 5.12.3 [ 106541 ]
            Affects Version/s New: 5.12.4 [ 106912 ]
            Affects Version/s New: 5.12.6 [ 107322 ]
            Affects Version/s New: 5.12.5 [ 107330 ]
            Affects Version/s New: 5.12.7 [ 107622 ]
            Affects Version/s New: 5.12.8 [ 108111 ]
            Affects Version/s New: 5.12.9 [ 107820 ]
            Affects Version/s New: 5.12.12 [ 108392 ]
            Affects Version/s New: 5.12.10 [ 108205 ]
            Affects Version/s New: 5.12.11 [ 108498 ]
            Affects Version/s New: 5.12.13 [ 108709 ]
            Affects Version/s New: 5.12.14 [ 109025 ]
            Affects Version/s New: 5.12.15 [ 109303 ]
            Affects Version/s New: 5.12.16 [ 109218 ]
            Affects Version/s New: 5.12.17 [ 110203 ]
            Affects Version/s New: 5.12.18 [ 110204 ]
            Affects Version/s New: 5.12.19 [ 110205 ]
            Yufei Zuo made changes -
            Description Original: This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 5.12.19 of Jira Service Management Data Center and Server.

            This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.7, allows an attacker to access local and remote content.

            Atlassian recommends that Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
             * Jira Service Management Data Center and Server 5.12: Upgrade to a release greater than or equal to 5.12.22

            See the release notes ([https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html]). You can download the latest version of Jira Service Management Data Center and Server from the download center ([https://www.atlassian.com/software/jira/service-management/download-archives]).

            This vulnerability was reported via our Atlassian (Internal) program.
            New: This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 5.12.0 of Jira Service Management Data Center and Server.

            This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.7, allows an attacker to access local and remote content.

            Atlassian recommends that Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
             * Jira Service Management Data Center and Server 5.12: Upgrade to a release greater than or equal to 5.12.22

            See the release notes ([https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html]). You can download the latest version of Jira Service Management Data Center and Server from the download center ([https://www.atlassian.com/software/jira/service-management/download-archives]).

            This vulnerability was reported via our Atlassian (Internal) program.
            Yufei Zuo made changes -
            Affects Version/s Original: 5.12.19 [ 110205 ]
            Affects Version/s New: 5.12.0 [ 105722 ]
            Yufei Zuo made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 1007346 ]
            Yufei Zuo made changes -
            Description Original: This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 5.12.19 of Jira Service Management Data Center and Server.

            This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.7, allows an attacker to access local and remote content.

            Atlassian recommends that Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
             * Jira Service Management Data Center and Server 9.12: Upgrade to a release greater than or equal to 9.12.22

            See the release notes ([https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html]). You can download the latest version of Jira Service Management Data Center and Server from the download center ([https://www.atlassian.com/software/jira/service-management/download-archives]).

            This vulnerability was reported via our Atlassian (Internal) program.
            New: This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 5.12.19 of Jira Service Management Data Center and Server.

            This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.7, allows an attacker to access local and remote content.

            Atlassian recommends that Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
             * Jira Service Management Data Center and Server 5.12: Upgrade to a release greater than or equal to 5.12.22

            See the release notes ([https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html]). You can download the latest version of Jira Service Management Data Center and Server from the download center ([https://www.atlassian.com/software/jira/service-management/download-archives]).

            This vulnerability was reported via our Atlassian (Internal) program.

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: