Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature. The affected versions are before version 4.13.9, and from version 4.14.0 before 4.18.0.
| Software | From | Fixed in |
|---|---|---|
| atlassian / jira_service_desk | - | 4.13.9 |
| atlassian / jira_service_management | 4.14.0 | 4.18.0 |