We recommend the update of Xray for Jira Server & Data Center to the 4.3.6 - latest version. |
Summary | Remote Code Execution on Document Generator Export |
---|---|
Advisory Release Date | 10:00 AM CET |
Product | Xray for Jira Server & Data Center |
Affected on versions |
|
Fixed on versions |
|
This advisory discloses a security vulnerability classified as critical that was present in Xray for Jira Server & Data Center. Versions of Jira Server & Data Center affected by this vulnerability:
Customers who have upgraded Xray for Jira Server & Data Center to version 4.3.3 or higher are not affected.
Customers who are on any of the affected versions, upgrade your Xray for Jira Server & Data Center installations immediately to fix this vulnerability.
We rate the severity level of this vulnerability as critical, according to the scale published in Bugcrowd’s Vulnerability Rating Taxonomy. The scale allows us to rank the severity as critical, high, moderate, or low.
This is our assessment and you should evaluate its applicability to your own IT environment.
We detected Remote Code Execution vulnerabilities on the Document Generator Export feature.
These issues can be tracked here:
We have released Xray for Jira Server & Data Center version 4.3.3 which is available for upgrade through the Atlassian Marketplace.
You can upgrade to the latest version of Xray for Jira Server & Data Center using the Universal Plugin Manager as explained in Updating apps.
If you have questions or concerns regarding this advisory, please raise a support request here.