CVE-2021-26068

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
22/02/2021
Last modified:
17/02/2022

Description

An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via a template injection vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atlassian:jira_server_for_slack:*:*:*:*:*:*:*:* 0.0.3 (including) 2.0.15 (excluding)