Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA Administrators access to execute arbitrary Java code via a server-side template injection vulnerability in the Email Template feature. The affected versions of Jira Server or Data Center are before version 8.13.12, and from version 8.14.0 before 8.19.1.
2021-09-16T06:15:06.833
2024-11-21T06:18:38.817
Modified
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | atlassian | jira_data_center | < 8.13.12 | Yes |
Application | atlassian | jira_data_center | < 8.19.1 | Yes |
Application | atlassian | jira_server | < 8.13.12 | Yes |
Application | atlassian | jira_server | < 8.19.1 | Yes |