Lucene search

K
atlassianSecurity-metrics-botJSDSERVER-8665
HistoryAug 25, 2021 - 4:24 a.m.

Template Injection in Email Templates leads to code execution on Jira Service Management Server - CVE-2021-39115

2021-08-2504:24:23
security-metrics-bot
jira.atlassian.com
20
jira service management
code execution
email templates
cve-2021-39115
atlassian jira server

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

62.1%

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with ā€œJira Administratorsā€ access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature.

The affected versions are before version 4.13.9, and from version 4.14.0 before 4.18.0.

Affected versions:

  • version < 4.13.9
  • 4.14.0 ā‰¤ version < 4.18.0

Fixed versions:

  • 4.13.9
  • 4.18.0

Affected configurations

Vulners
Node
atlassianjira_service_managementRangeā‰¤4.17.1data_center
OR
atlassianjira_service_managementRangeā‰¤4.13.8data_center
OR
atlassianjira_service_managementRangeā‰¤4.5.18data_center
OR
atlassianjira_service_managementRange<4.18.0data_center
OR
atlassianjira_service_managementRange<4.13.9data_center
VendorProductVersionCPE
atlassianjira_service_management*cpe:2.3:a:atlassian:jira_service_management:*:*:*:*:data_center:*:*:*

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

62.1%