CVE-2021-39128 Vulnerability Details

  /     /     /  

CVE-2021-39128 Metadata Quick Info

CVE Published: 16/09/2021 | CVE Updated: 10/10/2024 | CVE Year: 2021
Source: atlassian | Vendor: Atlassian | Product: Jira Server
Status : PUBLISHED

CVE-2021-39128 Description

Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA Administrators access to execute arbitrary Java code via a server-side template injection vulnerability in the Email Template feature. The affected versions of Jira Server or Data Center are before version 8.13.12, and from version 8.14.0 before 8.19.1.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-1336
CWE Name: CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine
Source: Atlassian

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).