CVE-2021-43947: Critical severity atlassian data center vulnerability
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of https://jira.atlassian.com/browse/JSDSERVER-8665. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-43947?
CVE-2021-43947 is a Remote Code Execution (RCE) vulnerability in the Email Templates feature of Atlassian Jira Server and Data Center.
How severe is CVE-2021-43947?
CVE-2021-43947 has a severity rating of 7.2, which is considered critical.
Which versions of Atlassian Jira Server and Data Center are affected by CVE-2021-43947?
Versions up to and excluding 8.13.15 of Atlassian Jira Server and Data Center are affected.
How can an attacker exploit CVE-2021-43947?
Remote attackers with administrator privileges can exploit CVE-2021-43947 to execute arbitrary code.
Is there a fix for CVE-2021-43947?
Yes, Atlassian has provided a fix for CVE-2021-43947. It is recommended to upgrade to a version that is not affected.