Lucene search

K
atlassian[email protected]ATLASSIAN:JRA-64077
HistoryFeb 13, 2017 - 4:43 a.m.

Multiple Vulnerabilities in JIRA Workflow Servlet

2017-02-1304:43:51
jira.atlassian.com
27

0.023 Low

EPSS

Percentile

89.8%

||Affected Versions||
|4.2.4 <= version < 6.3.0|

An anonymous user can perform multiple attacks on a vulnerable JIRA instance that could cause remote code execution, the disclosure of private files or execute a denial of service attack against the JIRA server. This vulnerability is caused by the way an XML parser and deserializer was used in JIRA.

For additional details see the [full advisory|https://confluence.atlassian.com/x/vzBoN].

0.023 Low

EPSS

Percentile

89.8%