Atlassian.Jira.Authenticated.Upload.Remote.Code.Execution

description-logoDescription

This indicates an attempt to execute a payload on Atlassian Jira via the Universal Plugin Manager.
Jira Universal Plugin Manager is designed for helping users manage their apps. An attacker with system administrator privileges could upload a malicious plugin through the plugin manager, leading to further attacks.

affected-products-logoAffected Products

Atlassian Jira via the Universal Plugin Manager

Impact logoImpact

System Compromise: Authenticated attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Restrict and audit the access to the Universal plugin manager

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2018-12-05 13.503 Default_action:pass:drop
2018-11-23 13.497

References

45851