{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aatlassianjira/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:*","cpe:2.3:a:atlassian:jira_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2019-11581"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Jira Server (\u003c 7.6.14, 7.13.5, 8.0.3, 8.1.2, 8.2.3)"],"_cs_severities":["critical"],"_cs_tags":["web-application-vulnerability","rce","ssti","jira"],"_cs_type":"threat","_cs_vendors":["Atlassian"],"content_html":"\u003cp\u003eCVE-2019-11581 is a critical Server-Side Template Injection (SSTI) vulnerability affecting multiple versions of Atlassian Jira Server. The flaw resides within the \u003ccode\u003eContactAdministrators.jspa\u003c/code\u003e functionality, which allows unauthenticated users to submit a contact form to administrators. The application insecurely processes the \u003ccode\u003esubject\u003c/code\u003e parameter by passing it to the Velocity templating engine for rendering. An attacker can supply a malicious Velocity template string as the subject, which is then executed by the server, leading to full Remote Code Execution (RCE) with the privileges of the Jira service process. The vulnerability was confirmed via public proof-of-concept exploits that utilize Velocity engine introspection to call \u003ccode\u003ejava.lang.Runtime.exec()\u003c/code\u003e. Defenders should prioritize patching, as the vulnerability requires no authentication and provides trivial access to the underlying host.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker navigates to the public-facing endpoint \u003ccode\u003e/secure/ContactAdministrators.jspa\u003c/code\u003e on a vulnerable Jira Server instance.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP POST request targeting the \u003ccode\u003eContactAdministrators\u003c/code\u003e form.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003esubject\u003c/code\u003e parameter in the request body is populated with a Velocity template payload (e.g., \u003ccode\u003e$i18n.getClass().forName('java.lang.Runtime')...\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe request is processed by the \u003ccode\u003eJiraWebworkActionDispatcher\u003c/code\u003e and routed to the \u003ccode\u003eContactAdministrators.doExecute()\u003c/code\u003e method.\u003c/li\u003e\n\u003cli\u003eThe application triggers \u003ccode\u003eEmailBuilder.renderLater()\u003c/code\u003e, which eventually calls \u003ccode\u003eDefaultVelocityTemplatingEngine.render()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe Velocity engine parses the malicious \u003ccode\u003esubject\u003c/code\u003e string as a template, invoking the injected Java reflection code.\u003c/li\u003e\n\u003cli\u003eThe system executes the arbitrary command, granting the attacker RCE on the server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full server compromise, allowing attackers to execute arbitrary system commands, exfiltrate sensitive Jira data, or use the compromised host as a pivot point in the internal network. The vulnerability impacts Atlassian Jira Server versions below 7.6.14, 7.13.5, 8.0.3, 8.1.2, and 8.2.3.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately upgrade all Atlassian Jira Server instances to the patched versions specified by Atlassian (7.6.14, 7.13.5, 8.0.3, 8.1.2, 8.2.3 or higher).\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, disable the \u003ccode\u003eContact Administrators Form\u003c/code\u003e functionality via the application properties administration panel.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules below to monitor web logs for suspicious POST requests containing Velocity template syntax.\u003c/li\u003e\n\u003cli\u003eReview access logs for non-standard or unexpected POST requests to \u003ccode\u003e/secure/ContactAdministrators.jspa\u003c/code\u003e.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-29T12:44:16Z","date_published":"2026-08-29T12:44:16Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2019-11581-jira-ssti/","summary":"An unauthenticated remote code execution vulnerability (CVE-2019-11581) exists in the 'ContactAdministrators' form of Atlassian Jira Server due to insecure Velocity template rendering of the 'subject' parameter.","title":"Unauthenticated RCE via Server-Side Template Injection in Atlassian Jira","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2019-11581-jira-ssti/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:atlassian:jira:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}