CVE-2021-43944

CWE-94Code Injection3 documents3 sources
Severity
7.2HIGH
EPSS
2.0%
top 16.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 8
Latest updateMar 9

Description

This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages4 packages

CVEListV5atlassian/jira_data_centerunspecified8.13.15+2
NVDatlassian/jira_data_center8.14.08.20.3+1
CVEListV5atlassian/jira_serverunspecified8.13.15+2
NVDatlassian/jira_server8.14.08.20.3+1

🔴Vulnerability Details

2
GHSA
GHSA-7gx3-2prj-gfr9: This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented2022-03-09
CVEList
CVE-2021-43944: This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented2022-03-08