First published: Tue Mar 08 2022(Updated: )
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.
Credit: security@atlassian.com security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Jira Data Center | <8.13.15 | |
Atlassian Jira Data Center | >=8.14.0<8.20.3 | |
Atlassian Jira Server | <8.13.15 | |
Atlassian Jira Server | >=8.14.0<8.20.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43944 is a security vulnerability in Atlassian Jira Server and Data Center that allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection.
Versions up to and including 8.13.15 of Atlassian Jira Server and Data Center are affected. Additionally, versions between 8.14.0 and 8.20.3 of Jira Server and Data Center are also affected.
CVE-2021-43944 has a severity score of 7.2, which is considered high.
To fix CVE-2021-43944, you should upgrade your Atlassian Jira Server or Data Center installation to a version beyond 8.20.3 or apply the necessary security patches provided by Atlassian.
You can find more information about CVE-2021-43944 at the Atlassian Jira bug tracker: https://jira.atlassian.com/browse/JRASERVER-73072