EXPOSURES › CVE-2019-11581
CVE-2019-11581
HIGH ⌖ ON CISA KEV · EXPLOITEDAtlassian Jira Server and Data Center suffered a server-side template injection vulnerability allowing remote code execution.
The vulnerability in Atlassian Jira Server and Data Center allowed attackers to execute arbitrary code remotely via server-side template injection. DIB organizations using Jira must ensure immediate patching to prevent remote code execution and potential data breaches. This failure highlights the risk of unpatched vulnerabilities in widely used collaboration tools.
Shame score — A known vulnerability allowing remote code execution in a widely deployed enterprise tool, though not linked to ransomware or data breach in this specific instance.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.