CVE-2021-43944

Description

This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.

Risk Information

Base Score
7.2
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.969

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2021-43941,CVE-2021-43944,CVE-2021-43945,CVE-2021-43952 are affected in Atlassian Jira 8.20.2Windows
Multiple Vulnerabilities are affected in Atlassian Jira Core Data Center *Windows
Vulnerabilities CVE-2021-43941,CVE-2021-43944,CVE-2021-43947 are affected in Atlassian Jira Core Data Center 8.20.2Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234