-
Type:
Public Security Vulnerability
-
Resolution: Fixed
-
Priority:
Highest
-
Affects Version/s: 9.15.2, 9.16.0, 9.17.0, 9.17.2, 10.0.0, 10.1.1, 11.3.8
-
Component/s: Security
-
9.3
-
Critical
-
CVE-2023-45133
-
Atlassian (Internal)
-
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
-
Jira Software Data Center
This is a vulnerability in a non-Atlassian Jira Software Data Cente dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
This vulnerability affects certain versions of Atlassian Jira Software Data Center. The @babel/traverse dependency is affected by CVE-2023-45133, which allows arbitrary code execution when Babel compiles specially crafted code using a vulnerable plugin.
Upgrade to a release greater than or equal to 11.3.10
This is a vulnerability in a non-Atlassian Jira Software Data Center dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.