CVE-2021-43944: Code Injection
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-43944?
CVE-2021-43944 is a security vulnerability in Atlassian Jira Server and Data Center that allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection.
What versions of Atlassian Jira Server and Data Center are affected by CVE-2021-43944?
Versions up to and including 8.13.15 of Atlassian Jira Server and Data Center are affected. Additionally, versions between 8.14.0 and 8.20.3 of Jira Server and Data Center are also affected.
What is the severity of CVE-2021-43944?
CVE-2021-43944 has a severity score of 7.2, which is considered high.
How can I fix CVE-2021-43944?
To fix CVE-2021-43944, you should upgrade your Atlassian Jira Server or Data Center installation to a version beyond 8.20.3 or apply the necessary security patches provided by Atlassian.
Where can I find more information about CVE-2021-43944?
You can find more information about CVE-2021-43944 at the Atlassian Jira bug tracker: https://jira.atlassian.com/browse/JRASERVER-73072