The WebWork 1 web application framework in Atlassian JIRA before 3.13.2 allows remote attackers to invoke exposed public JIRA methods via a crafted URL that is dynamically transformed into method calls, aka "WebWork 1 Parameter Injection Hole."
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-03-26 14:00
Updated : 2017-08-16 18:29
NVD link : CVE-2008-6531
Mitre link : CVE-2008-6531
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
atlassian
- jira