CVE-2021-39115
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature. The affected versions are before version 4.13.9, and from version 4.14.0 before 4.18.0.
Las versiones afectadas de Atlassian Jira Service Management Server y Data Center permiten a atacantes remotos con acceso "Jira Administrators" ejecutar código Java arbitrario o ejecutar comandos del sistema arbitrarios por medio de una vulnerabilidad de Server_Side Template Injection en la funcionalidad Email Template. Las versiones afectadas son anteriores a versión 4.13.9, y desde versión 4.14.0 hasta 4.18.0
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2021-08-16 CVE Reserved
- 2021-09-01 CVE Published
- 2021-09-09 First Exploit
- 2023-03-25 EPSS Updated
- 2024-10-11 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- CWE-96: Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://jira.atlassian.com/browse/JSDSERVER-8665 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/PetrusViet/CVE-2021-39115 | 2021-09-09 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Atlassian Search vendor "Atlassian" | Jira Service Desk Search vendor "Atlassian" for product "Jira Service Desk" | < 4.13.9 Search vendor "Atlassian" for product "Jira Service Desk" and version " < 4.13.9" | data_center |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Jira Service Desk Search vendor "Atlassian" for product "Jira Service Desk" | < 4.13.9 Search vendor "Atlassian" for product "Jira Service Desk" and version " < 4.13.9" | server |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Jira Service Management Search vendor "Atlassian" for product "Jira Service Management" | >= 4.14.0 < 4.18.0 Search vendor "Atlassian" for product "Jira Service Management" and version " >= 4.14.0 < 4.18.0" | data_center |
Affected
| ||||||
Atlassian Search vendor "Atlassian" | Jira Service Management Search vendor "Atlassian" for product "Jira Service Management" | >= 4.14.0 < 4.18.0 Search vendor "Atlassian" for product "Jira Service Management" and version " >= 4.14.0 < 4.18.0" | server |
Affected
|