peter bassill · operator
$ cve CVE-2017-5983 JSON

CVE-2017-5983

9.8
CRITICAL · CVSS 3.0 · EPSS 16.2% (pctl 97)

Patch early

EPSS 16.2% — above the 10% action threshold.

Description

The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS16.24% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2017-04-10
Last modified2026-06-17

Affected (1)

VendorProduct
atlassianjira

References

→ the Explorer  ·  watch your stack  ·  NVD