Today I received suspicious email talking about critical vulnerability of ScriptRunner for JIRA and providing bunch of links to learn more about it and see how to patch the affected version.
As it looked suspicious to me I did not click on the links but instead tried to google any news about ScriptRunner vulnerabilities and checked Adaptavist web site. I did not find any information supporting claims in the email I received so looks like it was a malicious email and I was right not to trust it.
Let me know if I am wrong and there is indeed some vulnerabilities in Scriptrunner that need to be patched. But if there is none just be careful of the emails like this being distributed to JIRA users.