PT-2017-16807 · Atlassian · Jira+1

Matt Hart

·

Publicado

2017-04-10

·

Atualizado

2017-04-15

·

CVE-2017-5983

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Atlassian JIRA Server versions prior to 6.3.0
Description The issue is related to the improper use of an XML parser and deserializer in the JIRA Workflow Designer Plugin. This allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.
Recommendations For versions prior to 6.3.0, update to version 6.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the JIRA Workflow Designer Plugin until a patch is applied.

Correção

RCE

DoS

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-5983

Produtos afetados

Jira
Jira Workflow Designer Plugin