CVE-2017-5983
Last modified
CVE-2017-5983 is a vulnerability of currently unknown severity. The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.. EPSS estimates a 16.24% chance of exploitation in the next 30 days.
Description
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Jira | 4.2.4 |
| Atlassian | Jira | 4.3 |
| Atlassian | Jira | 4.3.1 |
| Atlassian | Jira | 4.3.2 |
| Atlassian | Jira | 4.3.3 |
| Atlassian | Jira | 4.3.4 |
| Atlassian | Jira | 4.4 |
| Atlassian | Jira | 4.4.1 |
| Atlassian | Jira | 4.4.2 |
| Atlassian | Jira | 4.4.3 |
| Atlassian | Jira | 4.4.4 |
| Atlassian | Jira | 4.4.5 |
| Atlassian | Jira | 5.0 |
| Atlassian | Jira | 5.0.1 |
| Atlassian | Jira | 5.0.2 |
| Atlassian | Jira | 5.0.3 |
| Atlassian | Jira | 5.0.4 |
| Atlassian | Jira | 5.0.5 |
| Atlassian | Jira | 5.0.7 |
| Atlassian | Jira | 5.1 |
| Atlassian | Jira | 5.1.1 |
| Atlassian | Jira | 5.1.2 |
| Atlassian | Jira | 5.1.3 |
| Atlassian | Jira | 5.1.4 |
| Atlassian | Jira | 5.1.5 |
| Atlassian | Jira | 5.1.6 |
| Atlassian | Jira | 5.1.7 |
| Atlassian | Jira | 5.1.8 |
| Atlassian | Jira | 5.2 |
| Atlassian | Jira | 5.2.1 |
| Atlassian | Jira | 5.2.2 |
| Atlassian | Jira | 5.2.3 |
| Atlassian | Jira | 5.2.4 |
| Atlassian | Jira | 5.2.5 |
| Atlassian | Jira | 5.2.6 |
| Atlassian | Jira | 5.2.7 |
| Atlassian | Jira | 5.2.8 |
| Atlassian | Jira | 5.2.9 |
| Atlassian | Jira | 5.2.10 |
| Atlassian | Jira | 5.2.11 |
| Atlassian | Jira | 6.0 |
| Atlassian | Jira | 6.0.1 |
| Atlassian | Jira | 6.0.2 |
| Atlassian | Jira | 6.0.3 |
| Atlassian | Jira | 6.0.4 |
| Atlassian | Jira | 6.0.5 |
| Atlassian | Jira | 6.0.7 |
| Atlassian | Jira | 6.0.8 |
| Atlassian | Jira | 6.1 |
| Atlassian | Jira | 6.1.1 |
Showing 50 of 66 affected configurations. See NVD for the full list.
References
- http://codewhitesec.blogspot.com/2017/04/amf.htmlTechnical Description
- http://www.securityfocus.com/bid/97379Third Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/JRASERVER-64077Vendor Advisory
- https://www.kb.cert.org/vuls/id/307983Third Party Advisory, US Government Resource, VDB Entry
- http://codewhitesec.blogspot.com/2017/04/amf.htmlTechnical Description
- http://www.securityfocus.com/bid/97379Third Party Advisory, VDB Entry
- https://jira.atlassian.com/browse/JRASERVER-64077Vendor Advisory
- https://www.kb.cert.org/vuls/id/307983Third Party Advisory, US Government Resource, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5983?
How severe is CVE-2017-5983?
How do I fix CVE-2017-5983?
Are you affected by CVE-2017-5983?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
