7.2
CVSSv3

CVE-2021-39115

Published: 01/09/2021 Updated: 25/04/2022
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature. The affected versions are before version 4.13.9, and from version 4.14.0 prior to 4.18.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

atlassian jira service desk

atlassian jira service management

Github Repositories

Template Injection in Email Templates leads to code execution on Jira Service Management Server

CVE-2021-39115 Template Injection in Email Templates leads to code execution on Jira Service Management Server I) Bulding Mình đã hướng dẫn deploy + debug ở đây, các bạn có thể tham khảo II) Phân tích Trong Description của CVE này cũng đã nói rõ là bug nằm ở tính nă