Vulnerability record · CVE-2019-11581 · published 9 August 2019
CVE-2019-11581: Atlassian Jira Server and Data Center server-side template injection
Atlassian · Jira Server
Jira Server and Data Center contain a server-side template injection flaw in the ContactAdministrators and SendBulkMail actions. An attacker can inject template expressions that are evaluated server-side, leading to remote code execution on vulnerable installations. The affected range spans many releases from 4.4.0 up to before 8.2.3, so unpatched deployments are broadly exposed.
Description
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction, active exploitation per CISA KEV, and a very high EPSS probability make this an urgent patching priority.
What it is
Jira Server and Data Center contain a server-side template injection flaw in the ContactAdministrators and SendBulkMail actions. An attacker can inject template expressions that are evaluated server-side, leading to remote code execution on vulnerable installations. The affected range spans many releases from 4.4.0 up to before 8.2.3, so unpatched deployments are broadly exposed.
Impact
Successful exploitation gives the attacker remote code execution on the Jira host, allowing full compromise of confidentiality, integrity and availability of the application and its data.
Attack surface
The flaw is reachable over the network through the ContactAdministrators and SendBulkMail actions, with no authentication or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
The vulnerability is listed in CISA KEV with a 2022-03-07 addition date, and EPSS reports a 30-day exploitation probability of 0.84621 (99.7th percentile), indicating active exploitation in the wild. No ransomware campaign use is documented in the record.
What to do
- Upgrade Jira Server and Data Center to a fixed release: 7.6.14, 7.13.5, 8.0.3, 8.1.2 or 8.2.3 depending on your branch.
- If immediate patching is not possible, restrict network access to the Jira instance and disable or block the ContactAdministrators and SendBulkMail functionality.
- Monitor Atlassian advisories and the JRASERVER-69532 ticket for updated guidance and any backported fixes.
- Verify no unauthorized administrative accounts or outbound connections exist on Jira hosts, and rotate credentials if compromise is suspected.
Detection
- Review Jira application and access logs for unusual requests to ContactAdministrators and SendBulkMail endpoints, especially with template-like payloads.
- Hunt for unexpected child processes spawned by the Jira Java process (for example shells or scripting interpreters).
- Monitor for outbound network connections from Jira servers to unfamiliar hosts that could indicate post-exploitation activity.
- Check for anomalous file writes or new files in Jira web directories and temporary paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-11581 to the Known Exploited Vulnerabilities catalog on 7 March 2022 as "Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 7 September 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jira.atlassian.com/browse/JRASERVER-69532 | Issue TrackingVendor Advisory |
| https://jira.atlassian.com/browse/JRASERVER-69532 | Issue TrackingVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11581 | US Government Resource |
Track CVE-2019-11581 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-11581), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.