Server-Side Template Injection in Atlassian Jira Server and Data Center
CVE-2021-39128
Key Information:
- Vendor
Atlassian
- Vendor
- CVE Published:
- 16 September 2021
What is CVE-2021-39128?
A vulnerability in Atlassian Jira Server and Data Center allows remote attackers with JIRA Administrators access to execute arbitrary Java code. This is achieved through a server-side template injection flaw within the Email Template feature, affecting certain versions of the software. Attackers can exploit this vulnerability if they have administrative access, leading to severe security risks. Users are encouraged to update to unaffected versions to protect against potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jira Data Center < 8.13.12
Jira Data Center 8.14.0
Jira Data Center < 8.19.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved