[Blog](/blog)

Show links

Resources

[Blog](/blog)

[Breaches](/breaches)

[eBooks, reports, & more](/resources)

[Events](/events)

[News](/news)

[Risks and Vulnerabilities](/category/risks-and-vulnerabilities)

Show links

Categories

[Attack Surface Management](/category/attack-surface-management)

[Company News](/category/company-news)

[Compliance and Regulations](/category/compliance-and-regulations)

[Cybersecurity](/category/cybersecurity)

[Data Breaches](/category/data-breaches)

[DevOps](/category/devops)

[Human Cyber Risk](/category/human-cyber-risk)

[Risks and Vulnerabilities](/category/risks-and-vulnerabilities)

[Third-Party Risk Management](/category/third-party-risk-management)

[Vendor Risk Management](/category/vendor-risk-management)

[Jira Security Vulnerability CVE-2019-11581](/blog/jira-security-vulnerability-cve-2019-11581)

Publish date

July 25, 2025

{x} minute read

# Jira Security Vulnerability CVE-2019-11581

[Get a demo](/contact-sales)

[Free trial](/demo)

[Download the PDF guide](#)

[Free trial](/demo)

Written by

[Greg Pollock](/team/greg-pollock)

Director of Research and Insights

Greg is a CISA-certified cybersecurity researcher who holds multiple patents for data leak detection. His findings have been featured in The New York Times, Forbes, and Wired.

Reviewed by

[Kaushik Sen](/team/kaushik-sen)

Chief Marketing Officer

Kaushik has a background in software engineering, enterprise solution architecture, and data analytics. He brings a unique, data-driven perspective to cybersecurity education.

Table of contents

Free resource

###

[Download now](#)

On 10 July 2019, Atlassian [released a security advisory](https://community.atlassian.com/t5/Jira-articles/CVE-2019-11581-Critical-Security-Advisory-for-Jira-Server-and/ba-p/1128241) for a critical severity [vulnerability](/blog/vulnerability) in most versions of Jira Server and Jira Data Center. The vulnerability was introduced in version 4.4.0, released in 2011, and affects versions as recent as 8.2.2, released on 13 June 2019.

The good news is that users of Jira Cloud are not affected. But how many organizations are running Jira Server or Jira Data Center, and are vulnerable to this attack?

## Tens of Thousands of Potentially Affected Servers

Using data from Shodan.io, we identified approximately 50,000 potential instances of Jira. Of those, our further research confirmed just over 30,000 to be reachable Jira instances with version numbers. And of those, only 63 had versions that were safe from [CVE](/blog/cve)-2019-11581.

So as of the day after the advisory, the vast majority of internet accessible Jira Server instances had vulnerable versions. It would be nice to show a chart comparing patched and unpatched versions, but there are so few secure instances they are not visible to the human eye. Instead, here is a chart of the ten most common versions of Jira Server in the population we surveyed, none of which are in the list of fixed Jira Server versions.

We exported this data soon after the advisory was released. Since then administrators have continued to take steps to remediate their vulnerabilities, and there should be fewer vulnerable instances every day. An initial assessment of the prevalence of this risk, however, shows tens of thousands of instances potentially are potentially vulnerable, and that patching has been far from universal.

Because the vulnerability exploits the "Contact Administrators Form" for template injection, Atlassian also released guidance on a work around to disable this form. Some of the servers that have not been upgraded have been secured using this work around. However, in manually checking sites that appeared to have vulnerable versions, they generally had not been patched since our initial data collection and had not implemented evidence of compensating controls. The only website where the version had changed since our initial data collection was one belonging to NASA. Good job NASA! But in the vast majority of cases there was no evidence the owners had upgraded to a secure version.

Additionally, users could disable the "Contact Administrators Form." Again, in manually checking random sites, only one was seen that had a notice that this had been disabled.

The geographic distribution of servers with vulnerable versions is similar to the distribution of computing systems worldwide. Most are in the US, but vulnerable servers were detected in 134 different countries. Essentially every nation with a digital economy likely has Jira servers that could be affected by this vulnerability.

The hostnames for Jira Servers can provide insight into the types of organizations affected. Of the servers with vulnerable versions, 69 included .gov in the URL. Those servers were hosted in 16 different countries, creating potential risk for many government functions.

 

However many vulnerable servers there are today, there should be fewer tomorrow and fewer the day after that. That said, there are still a lot of potentially vulnerable Jira servers, and protecting against data loss due to this vulnerability requires knowing both whether your organization has a vulnerable instance and whether your vendors are running unpatched Jira servers.

**Contact us if you'd like to check your Jira Server or Jira Data Center editions for this vulnerability.**

Free resource

###

[Download now](#)

## Related posts

Learn more about the latest issues in cybersecurity.

Risks and Vulnerabilities

#### [25 Security Vulnerabilities That Have Defined the 2020s (Thus Far)](/blog/top-25-security-vulnerabilities-of-the-2020s)

From Log4j to SolarWinds, discover the 25 critical security vulnerabilities that have reshaped cybersecurity thus far in the 2020s.

[](/team/nicholas-sollitto)

[Nicholas Sollitto](#)

May 28, 2026

Risks and Vulnerabilities

#### [ServiceNow Vulnerabilities: CVE-2024-4789 and CVE-2024-5217](/blog/servicenow-vulnerabilities)

Learn about two critical vulnerabilities affecting the ServiceNow platform (CVE-2024-4789 and CVE-2024-5217) and how UpGuard can help.

[](/team/nicholas-sollitto)

[Nicholas Sollitto](#)

January 16, 2025

Risks and Vulnerabilities

#### [Everything Everywhere: Systemic Data Exposure in Supabase Apps](/blog/everything-everywhere-systemic-data-exposure-in-supabase-apps)

Supabase is a favorite of AI coding agents. It's also prone to misconfiguration. We studied more than 16,000 open databases to see what's leaking.

[](/team/greg-pollock)

[Greg Pollock](#)

September 25, 2026

Risks and Vulnerabilities

#### [Oracle Just Shipped 1,449 Security Patches in One Quarter. We Checked How Much of It Is Actually New.](/blog/oracle-just-shipped-1-449-security-patches-in-one-quarter-we-checked-how-much-of-it-is-actually-new)

Oracle's July 2026 update shipped 1,449 security patches — 2.8x its all-time record. We parsed 23 quarters of advisories to find out how much is truly new.

[](/team/greg-pollock)

[Greg Pollock](#)

July 22, 2026

Risks and Vulnerabilities

#### [Data leakage risks with DBHub MCP servers](/blog/data-leakage-risks-with-dbhub-mcp-servers)

UpGuard found exposed DBHub servers leaking live databases to the open internet—an early sign that MCP exposure is becoming a systemic data risk.

[](/team/greg-pollock)

[Greg Pollock](#)

July 20, 2026

Risks and Vulnerabilities

#### [Understanding and Mitigating CVE-2025-55182 (React2Shell)](/blog/understanding-and-mitigating-cve-2025-55182-react2shell)

CVE-2025-55182 is a critical unauthenticated RCE in React Server Components (CVSS 10.0). Check if your Next.js or React 19 app is vulnerable and patch now.

[](/team/edward-kost)

[Edward Kost](#)

December 14, 2025

[All posts](/blog)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](/contact-sales)

[Free trial](/demo)
