jira.atlassian.com
https://jira.atlassian.com/browse/JSDSERVER-8665 CVE-2021-39115
HIGH
Record summary
CVE-2021-39115 has a selected CVSS score of 7.2 (high); EIP currently links 1 repository PoC.
Description
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature. The affected versions are before version 4.13.9, and from version 4.14.0 before 4.18.0.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 11, 2024 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Jira Service Desk Data CenterBrowse Atlassian / Jira Service Desk Data Center | CVE List | Before 4.13.9 | affected |
| 4.14.0 | affected | ||
| Before 4.18.0 | affected | ||
Jira Service Desk ServerBrowse Atlassian / Jira Service Desk Server | CVE List | Before 4.13.9 | affected |
| 4.14.0 | affected | ||
| Before 4.18.0 | affected | ||
jira_service_deskBrowse atlassian / jira_service_deskDefault status: unknown | CVE List | Before 4.13.9 | affected |
jira_service_managementBrowse atlassian / jira_service_managementDefault status: unknown | CVE List | 4.14.0 to < 4.18.0 | affected |
Proofs of concept
1Repository PoCs
GitHubPetrusViet/CVE-2021-39115Repository PoCby PetrusVietStars: 48Not analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-39115