We wish to advise our customers of a vulnerability in Refined for Jira Service Management Server / Data Center. Affected versions are 3.2.0-3.5.6.
Risk Assessment
Our assessment for the vulnerability is Medium as per Atlassian’s rating, because to carry out an attack, the user needs admin privileges or otherwise trick an admin user.
The vulnerability would allow an attacker that had Jira admin or Refined Admin permissions to perform a directory path traversal attack by uploading the attack file as a logo or image.
If you have any questions regarding this, please reach out to us.
Fixed versions
This issue has been fixed in version 3.5.7. If you are currently on a lower version, we recommend to upgrade to the latest release or at least 3.5.7. Please note that if you upgrade via UPM, you will get the latest version. To upgrade to the lower ones you need to download the JAR file from the Atlassian marketplace and manually upload it in the UPM.