Vulnerability record · CVE-2022-36799 · published 1 August 2022
CVE-2022-36799: Atlassian Jira Server and Data Center template injection RCE
Atlassian · Jira Data Center
Jira Server and Data Center used the XStream library inside Velocity email templates, allowing template injection that could execute arbitrary code. Atlassian shipped a security improvement that blocks XStream-based code execution in those templates. The flaw matters because it gives a privileged account a path to full remote code execution on the Jira host.
Description
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. In this case the security improvement was to protect against using the XStream library to be able to execute arbitrary code in velocity templates. The affected versions are before version 8.13.19, from version 8.14.0 before 8.20.7, and from version 8.21.0 before 8.22.1.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with high confidentiality, integrity and availability impact, though it requires system administrator privileges.
What it is
Jira Server and Data Center used the XStream library inside Velocity email templates, allowing template injection that could execute arbitrary code. Atlassian shipped a security improvement that blocks XStream-based code execution in those templates. The flaw matters because it gives a privileged account a path to full remote code execution on the Jira host.
Impact
An attacker with system administrator permissions can execute arbitrary code on the Jira server, gaining control of the application host and any data or credentials it holds.
Attack surface
Reachable over the network through the Email Templates feature; the CVSS vector shows network access with high privileges required and no user interaction.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is 0.45277 (98.7th percentile), indicating elevated predicted exploitation activity.
What to do
- Upgrade Jira Server and Data Center to 8.13.19, 8.20.7, 8.22.1 or later as applicable.
- Restrict and audit system administrator accounts, since exploitation requires that privilege level.
- Review and limit who can edit Email Templates in Jira.
- Monitor for unexpected outbound connections or process execution from the Jira host.
Detection
- Alert on changes to Jira email templates and related configuration.
- Monitor Jira logs for Velocity or XStream template errors and unusual rendering activity.
- Baseline and review system administrator account activity, especially template edits followed by process creation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jira.atlassian.com/browse/JRASERVER-73582 | Issue TrackingVendor Advisory |
| https://jira.atlassian.com/browse/JRASERVER-73582 | Issue TrackingVendor Advisory |
Track CVE-2022-36799 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-36799), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.