CVE-2021-39115 Vulnerability Details

  /     /     /  

CVE-2021-39115 Metadata Quick Info

CVE Published: 01/09/2021 | CVE Updated: 11/10/2024 | CVE Year: 2021
Source: atlassian | Vendor: Atlassian | Product: Jira Service Desk Server
Status : PUBLISHED

CVE-2021-39115 Description

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature. The affected versions are before version 4.13.9, and from version 4.14.0 before 4.18.0.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-96
CWE Name: CWE-96: Improper Neutralization of Directives in Statically Saved Code ( Static Code Injection )
Source: Atlassian

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).