LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-11581: Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 7, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 7, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-11581 to its Known Exploited Vulnerabilities catalog on Mar 7, 2022, with a federal patch deadline of Sep 7, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.

CVE-2019-11581 is a server-side template injection vulnerability in Atlassian Jira Server and Data Center. Successful abuse can lead to remote code execution on the affected host. For IT and security teams running self-managed Jira, this matters because the product often holds project data, credentials, and integrations that an attacker could leverage after gaining code execution. Confirm all version and configuration details against the vendor advisory before acting.

How it works

The weakness is classed as CWE-74: improper neutralization of special elements in output used by a downstream component (injection). In server-side template injection, user-controlled input reaches a template engine without adequate sanitization or sandboxing. An attacker who can supply or influence template content may cause the engine to evaluate expressions or directives that execute unintended logic on the server.

In products like Jira Server and Data Center, this class of flaw can allow remote code execution when the injected template content is processed in a privileged context. Public detail on exact injection points and exploit mechanics is limited here; treat any proof-of-concept material cautiously and verify behavior only in isolated lab environments against the vendor’s description. Do not assume unauthenticated access or specific payload formats without confirmation from the advisory.

Am I affected? How to find it in your systems

Atlassian Jira Server and Data Center typically run on internal application servers, often behind reverse proxies or load balancers, and are used for issue tracking, workflows, and collaboration. Inventory every instance: check configuration management databases, software asset tools, container or VM inventories, and network scans for hosts listening on common Jira ports or presenting Jira HTTP banners and login pages.

Absence of obvious log noise does not prove safety; prioritize version inventory and advisory matching.

How to remediate

Patch first. Apply the updates Atlassian released for this issue, following the vendor instructions referenced in the CISA-required action. Schedule maintenance windows, take configuration and database backups, apply the fixed releases in non-production first if possible, then promote to production and verify service health.

After patching, harden for this weakness class:

If you can't patch immediately

Reduce exposure until you can update:

These controls lower risk; they do not replace the vendor update.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities can lead to full host compromise and data theft. If you suspect exploitation, isolate affected systems, preserve volatile evidence and logs, rotate credentials and tokens that Jira could access, and follow your incident-response plan, including notification obligations where applicable. Ransomware use is not documented for this CVE in the provided facts. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora while you continue internal investigation.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAtlassian · Jira Server and Data Center
WeaknessCWE-74
Added to CISA KEVMar 7, 2022
Federal patch deadlineSep 7, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities