Atlassian has released updates addressing two critical flaws in its Jira development and ticketing tool. One of the flaws is a critical URL path traversal vulnerability in Jira Service Desk. The other is an authenticated template injection vulnerability in the Jira Importers plugin (JIM) through which an attacker could remotely execute code on vulnerable servers running a vulnerable version of Jira Server or Jira Data Center. The issue appears to go back to version 7.0.10, released only months after the products launch in 2015.”]

