Please do not report security vulnerabilities through public Jira issues. To report a security issue, follow the guidelines from https://mariadb.com/docs/server/security/cve.
Sensitive security issues can be reported on https://hackerone.com/mariadb or sent directly to the persons responsible for MariaDB security: security [AT] mariadb (dot) org.