SB2021122820 - Server-side template injection in Jira Service Management Server



SB2021122820 - Server-side template injection in Jira Service Management Server

Published: December 28, 2021

Security Bulletin ID SB2021122820
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Code Injection (CVE-ID: CVE-2021-39115)

The vulnerability allows a remote privileged user to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation in the Email Template feature. A remote user with "Jira Administrators" access can execute arbitrary Java code or run arbitrary system commands by injecting the code via the Email Template feature.


Remediation

Install update from vendor's website.