Record summary

CVE-2021-39115 has a selected CVSS score of 7.2 (high); EIP currently links 1 repository PoC.

Description

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature. The affected versions are before version 4.13.9, and from version 4.14.0 before 4.18.0.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 11, 2024 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus
CVE ListBefore 4.13.9affected
4.14.0affected
Before 4.18.0affected
CVE ListBefore 4.13.9affected
4.14.0affected
Before 4.18.0affected

Default status: unknown

CVE ListBefore 4.13.9affected

Default status: unknown

CVE List4.14.0 to < 4.18.0affected

Proofs of concept

1

Repository PoCs

GitHubPetrusViet/CVE-2021-39115Repository PoCby PetrusVietStars: 48Not analyzed1 file

10.2 KiB

GitHub

PoC details

References

2