The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator permissions to gain remote code execution via a template injection vulnerability through the use of a crafted PUT request.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published: 2019-09-19T14:28:36.566766Z

Updated: 2024-09-16T23:55:54.513Z

Reserved: 2019-08-13T00:00:00

Link: CVE-2019-15001

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-09-19T15:15:15.500

Modified: 2022-04-22T19:53:31.783

Link: CVE-2019-15001

cve-icon Redhat

No data.