CVE-2010-1165

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
20/04/2010
Last modified:
11/04/2025

Description

Atlassian JIRA 3.12 through 4.1 allows remote authenticated administrators to execute arbitrary code by modifying the (1) attachment (aka attachments), (2) index (aka indexing), or (3) backup path and then uploading a file, as exploited in the wild in April 2010.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atlassian:jira:3.12:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira:3.12.1:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira:3.12.2:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira:3.12.3:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira:3.13:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira:3.13.1:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira:3.13.2:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira:3.13.3:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira:3.13.4:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira:3.13.5:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira:4.0:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:atlassian:jira:4.1:*:*:*:*:*:*:*