Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
Release 5.2.0
-
JIRAXPORTER 2021 Sprint 5, JIRAXPORTER 2021 Sprint 6
-
Description
Xporter for Jira Server is vulnerable to remote code execution on Export and Import Settings feature. A normal administrator can upload an arbitrary file to the server by importing settings from a malicious .zip file.
Â