Template injection in Jira Software Data Center and Jira Software Server - CVE-2022-36799
Published: March 22, 2023
Vulnerability identifier: #VU73938
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36799
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in the Email Templates feature. A remote authenticated administrator can inject arbitrary code into email template and execute it on the server.
Affected software
Jira Software Data Center
Jira Software Server
Jira Software Server
How to mitigate CVE-2022-36799
Install updates from vendor's website.
Jira Software Data Center - addressed in versions 8.13.19, 8.20.7, 8.22.1
Jira Software Server - addressed in versions 8.13.19, 8.20.7, 8.22.1
Jira Software Server - addressed in versions 8.13.19, 8.20.7, 8.22.1