Description Preview
The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 contains a Remote Code Execution (RCE) vulnerability. Remote attackers who can trick a system administrator into importing a malicious workflow can execute arbitrary code on the system. The vulnerability stems from the ability to use various problematic OSWorkflow classes as part of workflows, which can be exploited for code execution.
Overview
This vulnerability (CVE-2017-18113) affects the DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center versions prior to 8.18.1. It is classified as CWE-94 (Code Injection). The issue allows attackers to execute arbitrary code by crafting malicious workflow configurations that leverage unsafe conditions, validators, functions, and registers built into the OSWorkflow library and other Jira dependencies. The attack requires social engineering to convince a system administrator to import the malicious workflow. Once imported, the attacker can achieve remote code execution on the affected system.
Remediation
To remediate this vulnerability:
- Upgrade Jira Server or Jira Data Center to version 8.18.1 or later.
- If immediate upgrade is not possible, implement strict controls over workflow imports:
- Only allow trusted administrators to import workflows
- Carefully review all workflow imports before applying them
- Consider implementing network segmentation to limit the impact of a potential compromise
- Monitor system logs for suspicious activities related to workflow imports or configurations
- Implement the principle of least privilege for all Jira administrators
References
- Atlassian Jira Server Vulnerability Report: https://jira.atlassian.com/browse/JRASERVER-72660
- CWE-94 (Code Injection): https://cwe.mitre.org/data/definitions/94.html
- Atlassian Security Advisory: https://jira.atlassian.com/browse/JRASERVER-72660
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing
- Health Care & Social AssistanceHealth Care & Social Assistance
- Transportation & WarehousingTransportation & Warehousing
- Finance and InsuranceFinance and Insurance
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- Other Services (except Public Administration)Other Services (except Public Administration)
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Public AdministrationPublic Administration
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- ConstructionConstruction
- InformationInformation
- Retail TradeRetail Trade
- Wholesale TradeWholesale Trade
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- Educational ServicesEducational Services
- MiningMining
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- UtilitiesUtilities