Atlassian Jira是澳大利亚Atlassian公司的一套缺陷跟踪管理系统。该系统主要用于对工作中各类问题、缺陷进行跟踪管理。 Atlassian Jira存在安全漏洞,该漏洞允许远程攻击者可利用该漏洞与“Jira管理员”访问任意Java代码或运行任意系统命令,通过服务器端模板注入漏洞的电子邮件模板特性。受影响的版本为4.13.9之前的版本,4.14.0之前的版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Atlassian | Jira Service Desk Server | unspecified ~ 4.13.9 | - |
|
| Atlassian | Jira Service Desk Data Center | unspecified ~ 4.13.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Template Injection in Email Templates leads to code execution on Jira Service Management Server | https://github.com/PetrusViet/CVE-2021-39115 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-39119 | Atlassian Jira 授权问题漏洞 | |
| CVE-2021-39109 | Atlasian Atlasboard 路径遍历漏洞 |
No comments yet