CVE-2021-43959

MEDIUM

Atlassian Jira Service Management Server & Data Center <4.13.20 - SSRF

Title source: llm
STIX 2.1

Description

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of JSM Insight. When running in an environment like Amazon EC2, this flaw may be used to access to a metadata resource that provides access credentials and other potentially confidential information. The affected versions are before version 4.13.20, from version 4.14.0 before 4.20.8, and from version 4.21.0 before 4.22.2.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JSDSERVER-11898

Scores

CVSS v3 5.7
EPSS 0.0027
EPSS Percentile 51.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
atlassian/jira_service_desk < 4.13.20 (2 CPE variants)
atlassian/jira_service_management 4.14.0 - 4.20.8 (2 CPE variants)
Published Jul 26, 2022
Tracked Since Feb 18, 2026