CVE-2019-11581
KEVCRITICAL 9.8EPSS 84.6%
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 84.62% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-03-07
- Nuclei
- critical · CWE-74
- Published
- 2019-08-09
- Updated
- 2025-10-21
Proof-of-concept exploits (3)
- PetrusViet/CVE-2019-115816★ · 2021-11-29
- jas502n/CVE-2019-1158193★ · 2019-07-22
- kobs0N/CVE-2019-1158110★ · 2019-12-13
Nuclei templates (1)
Vulhub environments (1)
Exploit collections (2)
- chaitin/xray/blob/master/pocs/jira-cve-2019-11581.yml
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2019/CVE-2019-11581.yaml