SB2021122820 - Server-side template injection in Jira Service Management Server
Published: December 28, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Code Injection (CVE-ID: CVE-2021-39115)
The vulnerability allows a remote privileged user to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in the Email Template feature. A remote user with "Jira Administrators" access can execute arbitrary Java code or run arbitrary system commands by injecting the code via the Email Template feature.
Remediation
Install update from vendor's website.