Lucene search

K
atlassianSecurity-metrics-botATLASSIAN:JSDSERVER-8665
HistoryAug 25, 2021 - 4:24 a.m.

Template Injection in Email Templates leads to code execution on Jira Service Management Server - CVE-2021-39115

2021-08-2504:24:23
security-metrics-bot
jira.atlassian.com
30
jira
service management
security issue

EPSS

0.002

Percentile

62.1%

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with “Jira Administrators” access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature.

The affected versions are before version 4.13.9, and from version 4.14.0 before 4.18.0.

Affected versions:

  • version < 4.13.9
  • 4.14.0 ≤ version < 4.18.0

Fixed versions:

  • 4.13.9
  • 4.18.0

EPSS

0.002

Percentile

62.1%

Related for ATLASSIAN:JSDSERVER-8665