Arbitrary code execution (RCE) @babel/traverse dependency in Jira Software Data Center

XMLWordPrintable

    • 9.3
    • Critical
    • CVE-2023-45133
    • Atlassian (Internal)
    • CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    • Jira Software Data Center

      This is a vulnerability in a non-Atlassian Jira Software Data Cente dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

      This vulnerability affects certain versions of Atlassian Jira Software Data Center. The @babel/traverse dependency is affected by CVE-2023-45133, which allows arbitrary code execution when Babel compiles specially crafted code using a vulnerable plugin.

      Upgrade to a release greater than or equal to 11.3.10

      This is a vulnerability in a non-Atlassian Jira Software Data Center dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

              Assignee:
              Unassigned
              Reporter:
              Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: