PT-2017-16807 · Atlassian · Jira+1

Matt Hart

·

Published

2017-04-10

·

Updated

2017-04-15

·

CVE-2017-5983

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Atlassian JIRA Server versions prior to 6.3.0
Description The issue is related to the improper use of an XML parser and deserializer in the JIRA Workflow Designer Plugin. This allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.
Recommendations For versions prior to 6.3.0, update to version 6.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the JIRA Workflow Designer Plugin until a patch is applied.

Fix

RCE

DoS

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-5983

Affected Products

Jira
Jira Workflow Designer Plugin