Description
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin Royal Gallery Cross-Site Scripting (2.3)
Oracle JRE CVE-2013-1473 Vulnerability (CVE-2013-1473)
Ruby 7PK - Security Features Vulnerability (CVE-2015-3900)
WordPress Plugin DB Backup Directory Traversal (4.5)
WordPress Plugin MAZ Loader-Preloader Builder for WordPress SQL Injection (1.3.2)