We wish to advise our customers of a vulnerability in Refined for Jira Serer Service Management Server / Data Center. Affected versions are 3.0.0-3.1.4 and 3.2.0-3.25.12 6.
Risk Assessment
Our assessment for the vulnerability is Medium as per Atlassian’s rating, because to carry out an attack, the user needs admin privileges or otherwise trick an admin user.
The vulnerability would allow an attacker that had Jira admin or Refined Admin permissions to perform a zip directory path traversal attack by uploading the attack zip- file as a theme filelogo or image.
If you have any questions regarding this, please reach out to us.
...
This issue has been fixed in versions version 3.1.5 and 3.27. 14. If you are currently on a lower version, we recommend to upgrade to 3.1the latest release or at least 3.5, 3.2.14 or any 3.3 release.7. Please note that if you upgrade via UPM, you will get the latest version (3.3.x). To upgrade to the lower ones you need to download the JAR file from the Atlassian marketplace and manually upload it in the UPM.
...