Code Injection in Jira Service Management Server - CVE-2021-39115

 

Code Injection in Jira Service Management Server - CVE-2021-39115

Published: December 28, 2021


Vulnerability identifier: #VU59101
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-39115
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote privileged user to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation in the Email Template feature. A remote user with "Jira Administrators" access can execute arbitrary Java code or run arbitrary system commands by injecting the code via the Email Template feature.


Affected software

Jira Service Management Server

How to mitigate CVE-2021-39115

Install updates from vendor's website.

Jira Service Management Server - addressed in versions 4.13.9, 4.18.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins